A penetration tester gained access to a server room by dressing as an engineer from a known third-party vendor. Which of the following types of penetration tests was performed?
A penetration tester performed a physical penetration test.
Physical penetration testing involves gaining unauthorized access to a facility to assess security measures, which is exactly what the tester did by impersonating a vendor engineer to enter the server room.
This choice correctly identifies the type of penetration test conducted. The tester's method of dressing as an engineer from a third-party vendor to gain access to a restricted area exemplifies a physical penetration test. This type of test evaluates the effectiveness of physical security controls, such as access badges and personnel identification.
Integrated penetration testing refers to testing that combines both physical and digital security measures within an organization. Although the tester did gain physical access, the scenario specifically describes a tactic aimed solely at bypassing physical security, not an integrated approach that assesses both physical and digital vulnerabilities.
A partially known environment test is conducted when the tester has some knowledge of the system but does not know all details. In this scenario, the tester's method of access does not relate to system knowledge; rather, it focuses on the physical access gained through deception, thus making this option irrelevant.
A known environment test involves the tester having full knowledge of the system and its vulnerabilities, often including detailed information about the network and applications. The action of impersonating a vendor engineer does not pertain to knowledge of the system itself, but rather to the physical approach taken to access the server room.
The penetration tester employed a physical penetration test by using deception to gain unauthorized access to a secure area. This method highlights the vulnerabilities in physical security protocols, which are critical to safeguarding sensitive information and facilities. The other choices do not accurately reflect the nature or intent of the actions taken in this scenario.
Related Questions
View allA software engineering manager wants to scan the code for security vul...
An engineer needs to ensure that a script has not been modified before...
An organization experiences data loss after several employees traveled...
While working remotely, a manager is unable to access some shared fold...
Which of the following methods is the most effective for reducing vuln...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations