CISSP Security Assessment and Testing Practice Question
A company must comply with a regulation requiring a formal, independent assessment of its security controls against a standard. Which type of assessment is MOST appropriate?
⚠ Common exam trap
A common mix-up: candidates confuse a security audit with a penetration test or vulnerability assessment, mistakenly thinking that technical exploitation is required for compliance, when the regulation specifically demands an independent evaluation against a standard, not a technical attack simulation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security audit
A security audit is the most appropriate assessment because it is a formal, independent evaluation of an organization's security controls against a predefined standard (e.g., ISO 27001, NIST SP 800-53). Unlike other assessments, an audit is conducted by an independent third party or internal audit function, providing objective evidence of compliance with regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Penetration test
Why it's wrong here
A penetration test is an adversarial simulation designed to identify and exploit vulnerabilities within a system or network, demonstrating the real-world impact of a successful attack. Its primary objective is to uncover exploitable weaknesses and gauge an organization's resilience, not to systematically compare security controls against a predefined regulatory standard or framework. While valuable for risk assessment, it does not fulfill a formal compliance requirement for control verification.
- ✓
Security audit
Why this is correct
A security audit is a formal, independent, and systematic examination of an organization's security controls, processes, and policies against a specific set of criteria, such as regulatory requirements or industry standards. It involves evidence collection, analysis, and reporting to determine the extent of compliance and the effectiveness of controls. This structured, evidence-based approach, conducted by independent parties, is precisely what a regulation requiring a formal comparison of controls to a standard demands.
- ✗
Security review
Why it's wrong here
A security review is typically an internal, less formal examination of security practices, often conducted by internal staff to identify areas for improvement. It lacks the independence, structured methodology, and objective evidence collection required to formally verify compliance against a specific regulatory standard. Therefore, it would not satisfy a regulation demanding a formal, independent assessment comparing controls to a standard.
- ✗
Vulnerability assessment
Why it's wrong here
A vulnerability assessment systematically identifies potential security weaknesses and misconfigurations within systems, applications, or networks, often using automated scanning tools. Its focus is on discovering vulnerabilities and providing a prioritized list for remediation, rather than formally verifying adherence to specific compliance standards. While it informs security posture, it does not provide the independent, evidence-based attestation of control effectiveness required by a formal regulation.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.