Courseiva
Security Assessment and TestingeasyMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?

⚠ Common exam trap

Watch out — candidates often confuse vulnerability assessment with penetration testing, assuming that any active testing must include exploitation, but the CISSP exam emphasizes the distinction that vulnerability assessment stops at identification, while penetration testing includes exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vulnerability assessment

A vulnerability assessment is a systematic review of security weaknesses in a system or application, but it does not involve actively exploiting those weaknesses. The question specifies that the analyst is asked to identify vulnerabilities without attempting to exploit them, which directly matches the definition of a vulnerability assessment. This type of assessment typically uses automated scanners (e.g., Nessus, OpenVAS) and manual checks to enumerate potential vulnerabilities, such as missing patches or misconfigurations, without moving to the exploitation phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security review

    Why it's wrong here

    A security review involves a high-level, often proactive, examination of security documentation, system designs, configurations, or policies to identify potential weaknesses or non-compliance. This process typically does not involve active scanning or exploitation of live systems but rather a critical analysis of existing security artifacts. It aims to uncover architectural flaws or policy gaps that could lead to vulnerabilities, often performed early in the development lifecycle or as part of a governance process.

  • Vulnerability assessment

    Why this is correct

    A vulnerability assessment systematically scans systems, applications, and networks for known security weaknesses, configuration errors, and missing patches. It utilizes automated tools and manual analysis to identify potential flaws without attempting to exploit them. The primary goal is to provide a prioritized list of vulnerabilities that could be exploited, enabling organizations to proactively address risks before they are leveraged by attackers.

  • Security audit

    Why it's wrong here

    A security audit is a formal, systematic evaluation comparing an organization's security controls and practices against established policies, industry standards, or regulatory requirements. Its objective is to determine compliance, identify control deficiencies, and assess the effectiveness of implemented security measures. This process often involves reviewing documentation, interviewing personnel, and examining evidence of control operation, rather than actively scanning for technical vulnerabilities.

  • Penetration test

    Why it's wrong here

    A penetration test is an authorized, simulated cyberattack designed to actively exploit identified vulnerabilities in a system or network to determine the extent to which an attacker could gain unauthorized access or cause damage. Unlike a vulnerability assessment, it goes beyond identification by attempting to compromise systems, escalate privileges, and exfiltrate data. This process provides a realistic view of an organization's security posture and the potential business impact of a successful breach.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.