CISSP Security Assessment and Testing Practice Question
A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?
⚠ Common exam trap
Watch out — candidates often confuse vulnerability assessment with penetration testing, assuming that any active testing must include exploitation, but the CISSP exam emphasizes the distinction that vulnerability assessment stops at identification, while penetration testing includes exploitation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability assessment
A vulnerability assessment is a systematic review of security weaknesses in a system or application, but it does not involve actively exploiting those weaknesses. The question specifies that the analyst is asked to identify vulnerabilities without attempting to exploit them, which directly matches the definition of a vulnerability assessment. This type of assessment typically uses automated scanners (e.g., Nessus, OpenVAS) and manual checks to enumerate potential vulnerabilities, such as missing patches or misconfigurations, without moving to the exploitation phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security review
Why it's wrong here
A security review involves a high-level, often proactive, examination of security documentation, system designs, configurations, or policies to identify potential weaknesses or non-compliance. This process typically does not involve active scanning or exploitation of live systems but rather a critical analysis of existing security artifacts. It aims to uncover architectural flaws or policy gaps that could lead to vulnerabilities, often performed early in the development lifecycle or as part of a governance process.
- ✓
Vulnerability assessment
Why this is correct
A vulnerability assessment systematically scans systems, applications, and networks for known security weaknesses, configuration errors, and missing patches. It utilizes automated tools and manual analysis to identify potential flaws without attempting to exploit them. The primary goal is to provide a prioritized list of vulnerabilities that could be exploited, enabling organizations to proactively address risks before they are leveraged by attackers.
- ✗
Security audit
Why it's wrong here
A security audit is a formal, systematic evaluation comparing an organization's security controls and practices against established policies, industry standards, or regulatory requirements. Its objective is to determine compliance, identify control deficiencies, and assess the effectiveness of implemented security measures. This process often involves reviewing documentation, interviewing personnel, and examining evidence of control operation, rather than actively scanning for technical vulnerabilities.
- ✗
Penetration test
Why it's wrong here
A penetration test is an authorized, simulated cyberattack designed to actively exploit identified vulnerabilities in a system or network to determine the extent to which an attacker could gain unauthorized access or cause damage. Unlike a vulnerability assessment, it goes beyond identification by attempting to compromise systems, escalate privileges, and exfiltrate data. This process provides a realistic view of an organization's security posture and the potential business impact of a successful breach.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability assessment
A vulnerability assessment is a systematic review of security weaknesses in an information system, evaluating if the system is susceptible to any known vulnerabilities, assigning severity levels, and recommending remediation or mitigation.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.