Audit vs Vulnerability Assessment vs Penetration Test Flashcards
1
Q
Security Audit:
A
Definition:
Security Audit only inspects if an organization is following security standards and policies.
- essentially just checks for compliance
2
Q
Vulnerability Assessment:
A
Definition:
Vulnerability Assessment only deals with finding the vulnerabilities in the system/network.
- identifies vulnerabilities but doesn’t attempt to tell whether or not those vulnerabilities are exploitable in any particular instance, or what the potential harm to the system could be should it be exploited.
3
Q
Penetration Testing:
A
Definition:
Penetration Testing encompasses both the security audit and vulnerability assessment. It also demonstrates how hackers can exploit the identified vulnerabilities.
- also tells you which preventative measures can be taken to deter and prevent exploitation