New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 5 Question 97 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 97
Topic #: 5
[All CISSP Questions]

The overall goal of a penetration test is to determine a system's

Show Suggested Answer Hide Answer
Suggested Answer: B

The most important statement to convey to reviewers when setting expectations for reviewing the results of a security test is that the results of the tests represent a point-in-time assessment of the target(s). A security test is a process of evaluating and measuring the security posture and performance of an information system or a network, by using various tools, techniques, and methods, such as vulnerability scanning, penetration testing, or security auditing. The results of a security test reflect the security state of the target(s) at the time of the test, and they may not be valid or accurate for a different time period, as the security environment and conditions may change due to various factors, such as new threats, patches, updates, or configurations. Therefore, reviewers should understand that the results of a security test are not definitive or permanent, but rather indicative or temporary, and that they should be interpreted and used accordingly. The statement that the target's security posture cannot be further compromised is not true, as a security test does not guarantee or ensure the security of the target(s), but rather identifies and reports the security issues or weaknesses that may exist. The statement that the accuracy of testing results can be greatly improved if the target(s) are properly hardened is not relevant, as a security test is not meant to improve the accuracy of the results, but rather to assess the security of the target(s), and hardening the target(s) before the test may not reflect the actual or realistic security posture of the target(s). The statement that the deficiencies identified can be corrected immediately is not realistic, as a security test may identify various types of deficiencies that may require different levels of effort, time, and resources to correct, and some deficiencies may not be correctable at all, due to technical, operational, or financial constraints.


Contribute your Thoughts:

0/2000 characters
Buck
3 months ago
I thought error recovery was the focus, interesting!
upvoted 0 times
...
Rosendo
3 months ago
A is right, but D is also super important!
upvoted 0 times
...
Yvonne
3 months ago
Wait, are we sure it's not about capacity management?
upvoted 0 times
...
Janine
4 months ago
Definitely A, that's the main point of a pen test.
upvoted 0 times
...
Chanel
4 months ago
It's all about testing security!
upvoted 0 times
...
Kattie
4 months ago
I’m a bit confused; error recovery capabilities seem important too, but I don’t know if that’s the main goal of a pen test.
upvoted 0 times
...
Maxima
4 months ago
I feel like I’ve seen a similar question before, and I think it was about reliability under stress, which might relate to D.
upvoted 0 times
...
Jamie
4 months ago
I remember discussing capacity management in class, but I’m not sure it’s the primary focus of a penetration test.
upvoted 0 times
...
Twanna
5 months ago
I think the main goal of a penetration test is to see how well a system can withstand an attack, so I’m leaning towards A.
upvoted 0 times
...
Raina
5 months ago
This is a good question to test our understanding of penetration testing. I think the answer is A, but I'll double-check my notes just to be sure.
upvoted 0 times
...
Isabella
5 months ago
I'm a bit confused by the wording of the question. Is it asking about the overall goal of a penetration test, or something else? I'll need to re-read it a few times to make sure I understand.
upvoted 0 times
...
Vi
5 months ago
Okay, I've got this. The key is to focus on the "overall goal" of a penetration test, which is to assess the system's security and resilience against attacks. So the correct answer is A.
upvoted 0 times
...
Catalina
5 months ago
Hmm, I'm not entirely sure about this one. I'll need to think it through carefully before selecting an answer.
upvoted 0 times
...
Yolande
5 months ago
This seems like a straightforward question. The overall goal of a penetration test is to determine a system's ability to withstand an attack, so I'll go with option A.
upvoted 0 times
...
Isadora
10 months ago
Capacity management? Nah, that's just for the accountants. I'm all about that A, baby!
upvoted 0 times
...
Nettie
10 months ago
Definitely A. Penetration testing is all about pushing the system to its limits and seeing how it holds up.
upvoted 0 times
Michel
9 months ago
It's crucial to test the system's ability to withstand an attack before it's too late.
upvoted 0 times
...
Nada
9 months ago
I think A is the most important aspect to consider during a penetration test.
upvoted 0 times
...
Bo
9 months ago
I agree, it's important to see how the system reacts to different types of attacks.
upvoted 0 times
...
...
Dona
10 months ago
Ha! I bet the answer is C. Error recovery capabilities? That's what I always aim for in my systems!
upvoted 0 times
Bulah
9 months ago
User 3: I agree with Bulah, D) sounds like the right answer to me.
upvoted 0 times
...
Willodean
9 months ago
User 2: Really? I was leaning towards D) reliability under stress.
upvoted 0 times
...
Jerlene
9 months ago
User 1: I think the answer is actually A) ability to withstand an attack.
upvoted 0 times
...
...
Noel
10 months ago
I'm not sure, but I think it could be D. We want to know how reliable the system is under stress, right?
upvoted 0 times
Erick
9 months ago
Exactly, we want to make sure the system can handle stress and remain reliable.
upvoted 0 times
...
Kris
9 months ago
So the overall goal of a penetration test is to determine a system's ability to withstand an attack.
upvoted 0 times
...
Louvenia
10 months ago
Yes, that's correct. It's important to see how the system holds up during an attack.
upvoted 0 times
...
Anglea
10 months ago
I think you're right, we want to test the system's reliability under stress.
upvoted 0 times
...
...
Kirby
10 months ago
I think the answer is A. The goal of a penetration test is to find vulnerabilities and assess the system's ability to withstand attacks.
upvoted 0 times
...
Fernanda
10 months ago
I believe it's important to also consider the system's reliability under stress, so I would go with option D.
upvoted 0 times
...
Ryann
11 months ago
I agree with Yong, it's all about testing the system's security under attack.
upvoted 0 times
...
Yong
11 months ago
I think the overall goal is to determine a system's ability to withstand an attack.
upvoted 0 times
...

Save Cancel