ITPEC FE Morning April 2019 Question 44
ITPEC FE Morning April 2019 — Question 44 of 80
Penetration Testing — simulating real attacks to find vulnerabilities
Correct answer: a) Penetration test
A penetration test (pen test) involves actually attempting to exploit a system's vulnerabilities by simulating real-world attacks and intrusions. The goal is to identify security weaknesses before malicious actors do.
Why not the others:
- •b) Regression test — verifies that new code changes haven't broken existing functionality. It is a software development activity, not a security technique.
- •c) Software inspection — a static review technique where team members manually examine code or documents for defects. No attacks are performed.
- •d) Walk-through — the author of a document or code guides reviewers through it step by step. It is a review method, not a security assessment.
Key rule: If the question mentions "actually attempting an attack" or "simulating intrusion," the answer is always penetration test. Don't confuse it with vulnerability assessment (which only identifies weaknesses without exploiting them).
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.