Security OperationsQuestion 77 of 100
An authorized simulated attack that attempts to exploit vulnerabilities to test defenses is a:
a.Vulnerability scan
b.Compliance audit
c.Penetration test
d.Tabletop exercise
Explanation
A penetration test authorizes ethical hackers to actively exploit weaknesses to demonstrate real-world risk. It validates whether vulnerabilities are truly exploitable and how far an attacker could get. Rules of engagement define scope and limits.
Practice all 100 questions free — no signup required.
Related questions on this topic
- Which metric defines the maximum acceptable time to restore a service after an outage?
- Which recovery site is fully equipped and can take over operations almost immediately?
- Which scan identifies known weaknesses in systems without actively exploiting them?
- Which detection method flags activity that deviates from an established normal pattern?
- Which endpoint solution continuously records activity and enables investigation and automated response to threats on hosts?
- Which practice ensures logs cannot be tampered with by centralizing them on a protected, write-once server?
Last reviewed: · editorial process
Sen Lin, PrepPass Founder · Verified against CompTIA Security+ (SY0-701) · How we review