The PRIMARY reason for periodic penetration testing of Internet-facing applications is to:
I don’t see why B would be the primary reason here. Pen tests can reveal if new threats are affecting your stack, but their main job is to find real vulnerabilities like in D. B feels like a trap since it’s more about threat landscape awareness, not vulnerability discovery. Unless ISACA is testing for something subtle I missed?
Had something like this in a mock, and the answer was D. Pen tests are done mainly to find actual vulnerabilities exposed to the internet, not just check for new threats. Pretty sure that's what they're looking for here but open if I missed a detail.
I see why people are picking D, but I actually think B is tempting since pen tests also show us how new threats could impact our systems. Maybe I'm missing something about how CRISC wants "primary" reason defined here.