A company is expanding its threat surface program and allowing individuals to security test the company’s internet-facing application. The company will compensate researchers based on the vulnerabilities discovered. Which of the following best describes the program the company is setting up?
Choose an answer
Tap an option to check your answer.
Correct answer: Bug bounty.
Why this is the answer
A bug bounty program is a crowdsourcing initiative where organizations invite independent security researchers to discover and report vulnerabilities in their systems in exchange for monetary rewards or recognition. This aligns perfectly with the scenario described: compensating individuals for finding vulnerabilities in internet-facing applications. Open-source intelligence (OSINT) involves collecting information from publicly available sources, not actively testing systems for vulnerabilities. A red team is an authorized, simulated attack conducted by an internal or external team to test an organization's defenses, typically more comprehensive than individual vulnerability discovery. Penetration testing is a broader term for authorized simulated attacks to evaluate security, but a bug bounty specifically refers to the reward-based, crowdsourced model.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed