CISSP Practice Question (Domain 6: Security Assessment and Testing)
Leadership orders a penetration test of a customer-facing platform after a competitor's breach. Half the platform runs on a SaaS provider's infrastructure. The testing firm is contracted and ready to begin. What should the security manager confirm FIRST?
A. Authorization and scope boundaries from the SaaS provider
B. Rules of engagement defining escalation and stop conditions
C. Backups of production data before intrusive testing begins
D. Cyber liability coverage extends to testing activities
(Explain your answer for more points in the comments!)
Come back for the answer tomorrow, or study more now!
2
18 comments
Vincent Primiani
7
CISSP Practice Question (Domain 6: Security Assessment and Testing)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by