Courseiva
Security Assessment and TestingeasyMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

An organization wants to identify vulnerabilities in their network without attempting to exploit them. Which type of security assessment should they perform?

⚠ Common exam trap

Candidates often confuse a vulnerability assessment with a penetration test, assuming both involve exploitation, but the key differentiator is that a vulnerability assessment only identifies vulnerabilities, while a penetration test actively exploits them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vulnerability assessment

A vulnerability assessment is the correct choice because it is a systematic review of security weaknesses in a network or system that identifies vulnerabilities without actively exploiting them. This assessment typically uses automated scanning tools (e.g., Nessus, OpenVAS) to compare system configurations against known vulnerability databases (e.g., CVE, NVD) and reports potential issues, but does not attempt to gain unauthorized access or cause disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vulnerability assessment

    Why this is correct

    A vulnerability assessment systematically scans systems, networks, and applications to identify security weaknesses and misconfigurations. It uses automated tools and manual checks to detect known vulnerabilities, providing a prioritized list of potential risks without actively attempting to compromise the system. The goal is to inform remediation efforts by cataloging exposures and potential attack vectors, aligning precisely with the organization's desire to identify vulnerabilities without exploitation.

  • Penetration test

    Why it's wrong here

    A penetration test, or pen test, goes beyond identification by actively attempting to exploit discovered vulnerabilities to determine the actual impact and feasibility of an attack. This process simulates a real-world cyberattack, aiming to breach security controls and gain unauthorized access, which is a more intrusive and riskier activity than simply identifying weaknesses. The organization specifically stated they want to identify vulnerabilities, not exploit them, making this option unsuitable.

  • Security audit

    Why it's wrong here

    A security audit primarily focuses on evaluating an organization's adherence to established security policies, standards, regulations, and best practices. While it may indirectly uncover some weaknesses, its core purpose is to verify compliance and the effectiveness of controls against a defined framework, rather than systematically scanning for technical vulnerabilities in systems or applications. It's fundamentally a governance and compliance activity, not a direct vulnerability identification method.

  • Security review

    Why it's wrong here

    A security review typically involves a high-level, often informal, examination of security documentation, configurations, or processes to identify potential gaps or areas for improvement. Unlike a systematic vulnerability assessment, it generally lacks the comprehensive, tool-driven scanning and detailed technical analysis required to thoroughly identify specific, exploitable vulnerabilities across an organization's technical assets. It provides a less granular and less technical view than a dedicated vulnerability assessment.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.