Scan QR code or get instant email to install app
Question:
Setting off an alarm so that employees become used to it being a false positive is a technique that penetration testers may use if they can gain access to a facility. Once the staff is used to alarms going off and ignoring them, the penetration testers can enter areas that are alarmed without a response occurring. Setting off the alarm as part of a test isn’t typical for penetration testers, and disabling the alarm and waiting for the lack of an alarm to be reported is also more likely to be part of an internal test, not a penetration test. Asking staff members to open the door is not a means of making alarms less effective, and staff members who know the door is alarmed are unlikely to do so.
Comments