A utility CISO asks what threat-landscape-driven testing means compared with only hunting famous CVEs. Which statement best captures the CPTS-style emphasis?
Select an answer to reveal the explanation.
Short Explanation
Famous CVE bingo is the easy crossword; real testing is noticing the unlocked side door between systems. Misconfigs and trust chains often matter more than yesterday's headline bug. Hunt the path an attacker would actually use.
Full Explanation
CPTS-oriented judgment prioritizes discovering meaningful attack paths, including misconfigurations and chained weaknesses, rather than only confirming presence of widely publicized CVEs. Public PoCs are useful inputs, not a complete methodology. Scanner-only 'critical' filters and arbitrary recency cutoffs miss contextual risk. Configuration and trust issues frequently enable compromise without a glamorous CVE ID.