CISSP Security Assessment and Testing Practice Question
An organization requires a security assessment that evaluates controls against a specific standard and results in a formal report. The organization is not required to exploit vulnerabilities. Which type of assessment is this?
⚠ Common exam trap
It's easy for candidates to confuse a vulnerability assessment (which also does not exploit vulnerabilities) with a security audit, but the key differentiator is that an audit evaluates controls against a specific standard and produces a formal report, while a vulnerability assessment only identifies technical weaknesses without a compliance framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security audit
A security audit is a formal, independent evaluation of controls against a predefined standard (e.g., ISO 27001, PCI DSS) that produces a formal report. Unlike other assessments, it does not require exploiting vulnerabilities; it focuses on verifying compliance through evidence collection and testing. This matches the question's requirement for a standard-based evaluation with a formal report and no exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security audit
Why this is correct
A security audit is a systematic, independent examination of an organization's information system controls to determine whether they are operating effectively and in compliance with established criteria, such as regulatory requirements, industry standards, or internal policies. It is a formal, evidence-based process culminating in a comprehensive report detailing findings, recommendations, and an overall assessment of the security posture relative to the audit scope. This process is crucial for demonstrating due diligence and meeting governance objectives.
- ✗
Vulnerability assessment
Why it's wrong here
A vulnerability assessment is a process of identifying and quantifying security weaknesses within a system, network, or application. It typically involves automated scanning tools and manual analysis to detect known vulnerabilities, misconfigurations, and potential exposures. While it provides a crucial snapshot of technical risks, its primary goal is not to formally assess compliance against specific regulations or standards, nor does it involve actively exploiting the identified weaknesses.
- ✗
Penetration test
Why it's wrong here
A penetration test (pen test) is an authorized simulated cyberattack on a computer system, network, or web application to evaluate its security. Unlike a vulnerability assessment, a penetration test actively attempts to exploit identified vulnerabilities to determine if unauthorized access or other malicious activity is possible, thereby demonstrating the real-world impact of security weaknesses. Its primary objective is to prove the exploitability of vulnerabilities and assess the effectiveness of security controls, not primarily to audit compliance.
- ✗
Security review
Why it's wrong here
A security review is generally an informal, often ad-hoc, examination of specific security aspects, policies, or configurations within an organization. It typically involves discussions, document reviews, and observations aimed at identifying potential weaknesses or areas for improvement. Unlike a formal audit, a security review is less structured, may not follow a defined standard, and usually does not culminate in a formal, independently verifiable report intended for external stakeholders or compliance demonstration.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.