CISSP Security Assessment and Testing Practice Question
A penetration tester is engaged to assess a corporate wireless network. After capturing handshakes and attempting offline cracking, the tester obtains valid PSK credentials for the guest SSID. The tester then connects to the guest network but cannot reach any internal servers. Which of the following BEST describes what the tester has demonstrated?
⚠ Common exam trap
The trap here is assuming that a penetration test is only successful if internal systems are compromised, when containment itself is a reportable finding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The tester has achieved partial network access but is contained by network segmentation controls, which is a valid finding for the engagement.
Reaching only the guest segment after cracking its PSK shows the segmentation control is functioning and limits lateral movement. The engagement's value is in documenting both the credential weakness and the effective containment. A tester reports what was achieved within scope rather than treating lack of internal compromise as failure or escalating without authorization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The tester has achieved partial network access but is contained by network segmentation controls, which is a valid finding for the engagement.
Why this is correct
Compromising the guest PSK and being unable to reach internal resources demonstrates that the guest network is segmented from the internal environment. This is a genuine security finding because it shows the control is working as designed while also confirming credential compromise is possible. The tester should document both the successful PSK compromise and the effective segmentation.
- ✗
The tester has failed the engagement because no internal systems were compromised during the assessment.
Why it's wrong here
A penetration test is not graded solely on internal compromise. The scope defines success, and demonstrating that guest credentials can be cracked while segmentation holds is a legitimate result. Failing to reach internal systems does not mean the test failed; it means the segment boundary resisted lateral movement, which is itself evidence about control effectiveness.
- ✗
The tester should immediately escalate to a full internal penetration test without notifying the client because the guest network is a bridge to the internal environment.
Why it's wrong here
Any scope change, especially expanding into internal systems, requires explicit written authorization from the client. The tester cannot unilaterally pivot into new scope. Even if the guest network were a bridge, the rules of engagement govern what is permitted, and unauthorized escalation could be illegal and would violate professional ethics.
- ✗
The PSK compromise is irrelevant because guest networks are inherently untrusted and require no security controls.
Why it's wrong here
Guest networks still warrant security controls, including segmentation, credential management, and monitoring. Treating the PSK compromise as irrelevant ignores the risk that weak credentials could enable abuse such as bandwidth theft, malicious traffic origination, or use as a staging point. The finding has value because it documents a real weakness even if impact is limited.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.