Modules / Domain 6 — Security Assessment and TestingPractice Quiz: Assessment and TestingQuestion 1 of 3What must be obtained before any penetration test begins?A vulnerability scan reportWritten authorization from management defining scopeA signed non-disclosure agreement from the testers onlyApproval from the affected end usersQuestion 2 of 3A SOC 2 Type II report differs from a Type I report because it:Covers financial controls instead of securityIs a public marketing summaryTests operating effectiveness over a period of timeRequires no auditor involvementQuestion 3 of 3Which testing technique feeds malformed or random input to an application to find unhandled conditions?FuzzingStatic analysisRegression testingPort scanningAsk about this pagePreviousNext