exam questions

Exam PT0-003 All Questions

View all questions & answers for the PT0-003 exam

Exam PT0-003 topic 1 question 2 discussion

Actual exam question from CompTIA's PT0-003
Question #: 2
Topic #: 1
[All PT0-003 Questions]

Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?

  • A. The tester is conducting a web application test.
  • B. The tester is assessing a mobile application.
  • C. The tester is evaluating a thick client application.
  • D. The tester is creating a threat model.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
680e6b7
4 days, 2 hours ago
Selected Answer: D
DREAD is a risk assessment model used to quantify and prioritize threats based on five factors: Damage, Reproducibility, Exploitability, Affected Users, and Discoverability. It helps testers systematically evaluate risks and determine the severity of potential security issues. On the other hand, PTES (Penetration Testing Execution Standard) is a comprehensive framework that outlines the entire penetration testing process, including pre-engagement interactions, intelligence gathering, threat modeling, exploitation, and reporting. While PTES includes threat modeling as one of its phases, DREAD is specifically designed for risk assessment, making it the preferred choice when creating a threat model.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago