CISM Certified Information Security Manager – Question1359

The PRIMARY purpose of performing an internal attack and penetration test as part of an incident response program is to identify:

A.
weaknesses in network and server security.
B. ways to improve the incident response process.
C. potential attack vectors on the network perimeter.
D. the optimum response to internal hacker attacks.

Correct Answer: A

Explanation:

Explanation: An internal attack and penetration test are designed to identify weaknesses in network and server security. They do not focus as much on incident response or the network perimeter.