A security administrator is tasked with conducting an assessment made to establish the baseline security
posture of the corporate IT infrastructure. The assessment must report actual flaws and weaknesses in
the infrastructure. Due to the expense of hiring outside consultant, the testing must be performed usingin-house or cheaply available resources. There cannot be a possibility of equipment being damaged in the
test. Which of the following has the administrator been tasked to perform?

A.
Risk transference
B.
Penetration tes
C.
Threat assessment
D.
Vulnerability assessment
How is risk being transfered here?
This is either C or D
I would go with D
0
0
I agree.
0
0
Not risk transference
You could do a cheap pen test but it cannot damage the equipment–which means you need a passive test.
the Vulnerability assessment is largely a passive test so this is the winner.
0
0
D is correct
0
0