15. A penetration tester is testing the security of a building's alarm system following reports of unauthorized personnel entering the building. Which of the following describes the type of penetration test that is being conducted?
Answer: A
Physical
The type of penetration test being conducted is a physical penetration test, which focuses on assessing the security measures protecting a physical location, such as the building's alarm system. This test aims to identify vulnerabilities that could be exploited by unauthorized personnel.
A) Physical
This option is correct because it specifically refers to the testing of physical security measures, such as alarm systems, locks, and access controls in a building. The scenario describes a situation where unauthorized access has been reported, making a physical penetration test the appropriate method to evaluate the effectiveness of the building's security systems.
B) Defensive
Defensive penetration testing focuses on evaluating an organization's security posture and response mechanisms rather than directly testing physical security measures. Since the question pertains to assessing the alarm system and unauthorized access, this option does not apply to the scenario.
C) Integrated
Integrated penetration testing typically combines multiple types of testing, such as both physical and digital assessments. However, the context of the question specifically involves physical security concerns, making this option less relevant compared to option A.
D) Continuous
Continuous penetration testing refers to an ongoing assessment process that continually evaluates security measures over time. While this approach is beneficial for maintaining security, it does not directly describe the specific type of test being conducted in the scenario, which is focused on a singular physical assessment.
Conclusion
In summary, the correct answer is A) Physical, as it accurately describes the nature of the penetration test being conducted on the building's alarm system. The other options—Defensive, Integrated, and Continuous—do not directly pertain to the context of assessing physical security measures against unauthorized access.