ある企業は、評価チームを雇って、企業ネットワークのセキュリティと従業員の警戒をテストしました。最高経営責任者と最高執行責任者のみがこの演習を認識しており、評価者にはほとんど情報が提供されていません。行われているのは次のうちどれですか。
正解:A
A red-team test is a type of security assessment that simulates a real-world attack on an organization's network, systems, applications, and people. The goal of a red-team test is to evaluate the organization's security posture, identify vulnerabilities and gaps, and test the effectiveness of its detection and response capabilities. A red-team test is usually performed by a group of highly skilled security professionals who act as adversaries and use various tools and techniques to breach the organization's defenses. A red-team test is often conducted without the knowledge or consent of most of the organization's staff, except for a few senior executives who authorize and oversee the exercise.