Leadership reviews only automated vulnerability-scan scores for the courts case-management system and calls the program a full penetration test. What correction should the assessor make?
Select an answer to reveal the explanation.
Short Explanation
A scan is a checklist of weak locks; a pentest tries the picks. Courts systems need the right mix for the risk—not a rebrand of scan scores. Treating them as identical, quitting scans, or dumping raw CVEs publicly misses the point.
Full Explanation
Vulnerability assessment and penetration testing are related but distinct control tests. VA identifies known deficiencies; pentesting evaluates whether weaknesses can be exploited under agreed rules. Labeling scan output as a full pentest misleads risk owners. Eliminating scanning or publishing uncontextualized CVE dumps does not create a sound assessment mix for sensitive case-management systems.