A vendor provides your organization with a penetration test report conducted on their own systems. What is the primary limitation of this approach?
-
A
Penetration tests are not recognized by compliance frameworks
-
B
The report may lack independence since the vendor selected and scoped the test
-
C
Penetration tests do not cover application-layer vulnerabilities
-
D
The report is only valid for 30 days after issuance