hardMultiple ChoiceObjective-mapped
CISSP Practice Question: A financial institution is required to perform…
A financial institution is required to perform regular penetration tests on its online banking platform. The testing must be as realistic as possible while minimizing risk to production data. Which of the following approaches BEST meets these requirements?
⚠ Common exam trap
Watch out — candidates often choose Option A or C because they focus on 'realistic' testing and assume production is the only way to achieve realism, overlooking that a well-constructed replica provides identical attack surfaces without the unacceptable risk to production integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Build a replica of the production environment and test against it with realistic attack scenarios.
Building a replica (staging) environment allows the penetration test to simulate realistic attack scenarios without any risk to production data or system availability. This approach ensures the test can include destructive or disruptive techniques (e.g., SQL injection, privilege escalation) that would be unsafe on a live system, while still accurately reflecting the production architecture and configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct the test on the production environment using anonymized production data.
Why it's wrong here
Conducting a penetration test directly on the production environment, even with anonymized data, introduces unacceptable risks to system stability, availability, and data integrity. Penetration tests are inherently intrusive and can lead to service disruptions, system crashes, or unintended data corruption, regardless of data anonymization. Anonymization primarily addresses confidentiality concerns, not the operational risks associated with aggressive testing against live infrastructure, which violates the principle of minimizing impact on critical business operations.
- ✗
Use an automated vulnerability scanner on the production environment.
Why it's wrong here
Using an automated vulnerability scanner on the production environment is not a substitute for a comprehensive penetration test. While scanners efficiently identify known vulnerabilities and misconfigurations, they lack the adaptive, creative, and multi-stage attack methodologies of human testers. Automated tools cannot chain vulnerabilities, exploit complex business logic flaws, or creatively bypass security controls, which are crucial aspects of simulating a real-world, goal-oriented attack.
- ✗
Perform the test during off-peak hours on the production system with read-only access.
Why it's wrong here
Performing a penetration test with read-only access on a production system severely limits the scope and realism of the assessment. This restriction confines testers to passive reconnaissance and information gathering, preventing any attempts at exploitation, privilege escalation, or data exfiltration. A true penetration test requires the ability to simulate actual attacker actions, which often involve modifying system states or data, thus rendering read-only access insufficient for a meaningful security posture evaluation.
- ✓
Build a replica of the production environment and test against it with realistic attack scenarios.
Why this is correct
Building a high-fidelity replica of the production environment provides a safe, isolated sandbox to conduct aggressive, full-scope penetration tests without jeopardizing the stability, availability, or integrity of the live production system or its sensitive data. This approach enables testers to simulate realistic, multi-vector attack scenarios, including exploitation and post-exploitation activities, to thoroughly assess defenses and identify vulnerabilities under conditions mirroring actual threats, ensuring comprehensive security validation.
Go deeper
Related to this question
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.