A penetration tester gained access to a server room by dressing as an engineer from a known third-party vendor. Which of the following types of penetration tests was performed?
A penetration tester performed a physical penetration test.
Physical penetration testing involves gaining unauthorized access to a facility to assess security measures, which is exactly what the tester did by impersonating a vendor engineer to enter the server room.
This choice correctly identifies the type of penetration test conducted. The tester's method of dressing as an engineer from a third-party vendor to gain access to a restricted area exemplifies a physical penetration test. This type of test evaluates the effectiveness of physical security controls, such as access badges and personnel identification.
Integrated penetration testing refers to testing that combines both physical and digital security measures within an organization. Although the tester did gain physical access, the scenario specifically describes a tactic aimed solely at bypassing physical security, not an integrated approach that assesses both physical and digital vulnerabilities.
A partially known environment test is conducted when the tester has some knowledge of the system but does not know all details. In this scenario, the tester's method of access does not relate to system knowledge; rather, it focuses on the physical access gained through deception, thus making this option irrelevant.
A known environment test involves the tester having full knowledge of the system and its vulnerabilities, often including detailed information about the network and applications. The action of impersonating a vendor engineer does not pertain to knowledge of the system itself, but rather to the physical approach taken to access the server room.
The penetration tester employed a physical penetration test by using deception to gain unauthorized access to a secure area. This method highlights the vulnerabilities in physical security protocols, which are critical to safeguarding sensitive information and facilities. The other choices do not accurately reflect the nature or intent of the actions taken in this scenario.
Related Questions
View allAn employee from the accounting department logs in to the website used...
An administrator implements web-filtering products but still sees that...
Visitors to a company's facilities are connecting to the company's cor...
A user downloads a patch from an unknown repository to update their de...
Which of the following is a benefit of vendor diversity?
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations