Which type of assessment can detect software vulnerabilities, identify unsupported operating system versions, unused services that should be disabled, and configuration weaknesses that may pose security risks?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AA compliance audit checks controls against a specific standard or regulation, not a broad technical sweep for flaws.
- BPenetration testing goes beyond listing weaknesses to actively exploit them, so a broad inventory of flaws is not its main goal.
- CRisk assessment weighs likelihood and business impact of threats, using vulnerability data as an input rather than producing it.
- DCorrect: a vulnerability assessment systematically identifies missing patches, unsupported systems, needless services and misconfigurations without exploiting them.