Courseiva
Security Assessment and TestingmediumMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

An organization requires a security assessment that evaluates controls against a specific standard and results in a formal report. The organization is not required to exploit vulnerabilities. Which type of assessment is this?

⚠ Common exam trap

It's easy for candidates to confuse a vulnerability assessment (which also does not exploit vulnerabilities) with a security audit, but the key differentiator is that an audit evaluates controls against a specific standard and produces a formal report, while a vulnerability assessment only identifies technical weaknesses without a compliance framework.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security audit

A security audit is a formal, independent evaluation of controls against a predefined standard (e.g., ISO 27001, PCI DSS) that produces a formal report. Unlike other assessments, it does not require exploiting vulnerabilities; it focuses on verifying compliance through evidence collection and testing. This matches the question's requirement for a standard-based evaluation with a formal report and no exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security audit

    Why this is correct

    A security audit is a systematic, independent examination of an organization's information system controls to determine whether they are operating effectively and in compliance with established criteria, such as regulatory requirements, industry standards, or internal policies. It is a formal, evidence-based process culminating in a comprehensive report detailing findings, recommendations, and an overall assessment of the security posture relative to the audit scope. This process is crucial for demonstrating due diligence and meeting governance objectives.

  • Vulnerability assessment

    Why it's wrong here

    A vulnerability assessment is a process of identifying and quantifying security weaknesses within a system, network, or application. It typically involves automated scanning tools and manual analysis to detect known vulnerabilities, misconfigurations, and potential exposures. While it provides a crucial snapshot of technical risks, its primary goal is not to formally assess compliance against specific regulations or standards, nor does it involve actively exploiting the identified weaknesses.

  • Penetration test

    Why it's wrong here

    A penetration test (pen test) is an authorized simulated cyberattack on a computer system, network, or web application to evaluate its security. Unlike a vulnerability assessment, a penetration test actively attempts to exploit identified vulnerabilities to determine if unauthorized access or other malicious activity is possible, thereby demonstrating the real-world impact of security weaknesses. Its primary objective is to prove the exploitability of vulnerabilities and assess the effectiveness of security controls, not primarily to audit compliance.

  • Security review

    Why it's wrong here

    A security review is generally an informal, often ad-hoc, examination of specific security aspects, policies, or configurations within an organization. It typically involves discussions, document reviews, and observations aimed at identifying potential weaknesses or areas for improvement. Unlike a formal audit, a security review is less structured, may not follow a defined standard, and usually does not culminate in a formal, independently verifiable report intended for external stakeholders or compliance demonstration.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.