Thread Content
7.20--CAESARII Daily Topic: A certain organization has developed a web application to provide services over the Internet. It commissioned a software testing agency to conduct software security tests such as source code analysis and fuzz testing on this software. Before the application was launched, the project manager suggested that a penetration test should also be carried out on the web application. As the person in charge of security, you need to outline the advantages of penetration testing compared to source code testing and fuzz testing, so that management can make an informed decision. Which of the following is an advantage of penetration testing? A. Penetration testing simulates real attacks from an attacker’s perspective, enabling the detection of vulnerabilities that arise during operation and maintenance, such as configuration errors. B. Penetration testing is a testing method that uses software instead of human testers, thus making it more efficient. C. Penetration testing relies on human testers rather than software, which makes it more accurate. D. Penetration testing requires access to the software’s source code, resulting in the discovery of more vulnerabilities. A. Penetration testing simulates real attacks from an attacker’s perspective, enabling the detection of vulnerabilities that arise during operation and maintenance, such as configuration errors
A certain organization developed an application website to provide services over the Internet. It commissioned a software testing agency to conduct software security tests such as source code analysis and fuzz testing. Before the application was launched, the project manager suggested that a penetration test also be carried out on the website. As the person in charge of security, you need to outline the advantages of penetration testing compared to source code testing and fuzz testing, so that management can make an informed decision. Which of the following is an advantage of penetration testing? (A) A. Penetration testing simulates real attacks from an attacker’s perspective, enabling the detection of vulnerabilities that arise during operation and maintenance, such as configuration errors. B. Penetration testing is a testing method that uses software instead of human testers, thus making it more efficient. C. Penetration testing relies on human testers rather than software, which results in more accurate tests. D. Penetration testing requires access to the software’s source code, which allows for the discovery of more vulnerabilities