QuestionQ62

Report Writing and Post Testing Actions

Penetration testers must follow predefined standard frameworks when creating penetration-testing report formats.

Which of the following standards does not follow the commonly used methodologies for penetration testing?

  • A National Institute of Standards and Technology (NIST)
  • B Information Systems Security Assessment Framework (ISSAF)
  • C Open Web Application Security Project (OWASP)
  • D American Society for Testing Materials (ASTM)
Explanation

NIST, ISSAF, and OWASP are associated with information-security assessment or penetration-testing methodologies. ASTM International develops broad voluntary consensus standards, principally for technical products, materials, systems, and services, rather than a commonly used penetration-testing methodology.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!