Courseiva

CISSP · domain

Security Assessment and Testing

This domain covers how organizations design and run security assessments to find weaknesses before attackers do. You must distinguish vulnerability assessment from penetration testing, static from dynamic analysis, and understand audit logging, continuous monitoring, and control testing. Questions present scenarios and ask which technique, tool category, or assessment type fits the stated goal.

53 questions14 easy23 medium16 hard

Focused practice

Practice Security Assessment and Testing questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Assessment and Testing

Be able to match a stated goal to the right assessment type or tool category, especially scan versus exploit and static versus dynamic analysis. The single most important thing: read whether the scenario requires exploiting a vulnerability or only identifying it.

Choosing vulnerability assessment versus penetration testing based on whether exploitation is required

Selecting SAST for source code review without executing the program, versus DAST for running applications

Identifying runtime application self-protection (RASP) that instruments an application to monitor and block attacks

Applying audit logging, log review, and continuous monitoring to detect and investigate security events

Watch out for

Common Security Assessment and Testing exam traps

  • ▸Confusing vulnerability assessment with penetration testing: scanning finds weaknesses, while penetration testing attempts exploitation to prove impact
  • ▸Mixing up SAST and DAST: SAST reads source code without running it, DAST tests a running application from the outside
  • ▸Assuming a scan alone proves exploitability, or that a clean scan means no vulnerabilities exist in the assessed scope

Question index

All Security Assessment and Testing questions (53)

Click any question to see the full explanation, or start a practice session above.

1

A security team is selecting tools for code review. Which THREE of the following are characteristics of Static Application Security Testing (SAST) tools?

Hard
2

Which type of SOC report provides a public summary of an organization's controls over security, availability, and confidentiality?

Easy
3

Which THREE of the following are common key performance indicators (KPIs) used in security assessment and testing?

Hard
4

An organization requires a security assessment that evaluates controls against a specific standard and results in a formal report. The organization is not required to exploit vulnerabilities. Which type of assessment is this?

Medium
5

A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?

Hard
6

Which vulnerability scoring system provides a standardized severity rating for vulnerabilities based on exploitability and impact metrics?

Medium
7

Which of the following is a key element of the rules of engagement for a penetration test?

Easy
8

A company wants to ensure its internal web application is free from security flaws during development. Which testing approach analyzes source code without executing the program?

Hard
9

A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?

Medium
10

Which of the following is a key component of the rules of engagement for a penetration test?

Easy
11

A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:

Medium
12

An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?

Hard
13

An organization wants to test its security controls by simulating an attack where the tester has no prior knowledge of the internal network. This is known as a:

Easy
14

A company is planning to conduct a penetration test. Which THREE of the following should be included in the rules of engagement?

Medium
15

A company must comply with a regulation requiring a formal, independent assessment of its security controls against a standard. Which type of assessment is MOST appropriate?

Easy
16

A security analyst is reviewing logs from multiple systems and needs to ensure that logs are tamper-proof and available for incident investigation. Which of the following is the BEST approach?

Hard
17

Which TWO of the following are characteristics of a SOC 2 Type II report?

Medium
18

During a penetration test, the tester gains initial access to a server and then attempts to pivot to other systems. Which phase of the penetration testing process does this represent?

Hard
19

Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?

Easy
20

A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?

Easy
21

Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?

Hard
22

A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:

Easy
23

During a penetration test, the tester has obtained initial access and is now trying to move laterally to other systems. Which phase of the penetration testing process does this represent?

Medium
24

An organization wants to identify vulnerabilities in their network without attempting to exploit them. Which type of security assessment should they perform?

Easy
25

Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?

Easy
26

A security analyst is setting up a vulnerability scanning program. Which TWO of the following are best practices for determining scanning frequency?

Medium
27

A security manager is designing a continuous monitoring program to satisfy ongoing authorization requirements. The program must detect unauthorized configuration changes to production servers, verify that security patches are applied within policy timeframes, and provide evidence for auditors. Which TWO of the following controls BEST support these objectives? (Choose two.)

Hard
28

Which of the following is the primary purpose of a security audit?

Easy
29

A security analyst is conducting a vulnerability scan of a web application. The scan identifies several vulnerabilities, but the analyst wants to minimize false positives. Which type of vulnerability scan would be most appropriate?

Medium
30

During a SOC 2 audit, the auditor evaluates controls over a period of time to assess their operating effectiveness. Which type of SOC report is being performed?

Hard
31

An organization is required to retain security logs for a minimum of one year to meet compliance regulations. Which practice is most directly related to this requirement?

Medium
32

Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?

Medium
33

A penetration tester is engaged to assess a corporate wireless network. After capturing handshakes and attempting offline cracking, the tester obtains valid PSK credentials for the guest SSID. The tester then connects to the guest network but cannot reach any internal servers. Which of the following BEST describes what the tester has demonstrated?

Medium
34

After a penetration test, the tester provides a report that includes vulnerabilities found, exploitation details, and recommended fixes. Which step of the penetration testing process does this represent?

Hard
35

During a penetration test, the tester successfully exploits a vulnerability in a web server and gains initial access. The next step in the penetration testing process is to:

Easy
36

A security analyst is tasked with identifying vulnerabilities in a network without exploiting them. Which type of assessment is most appropriate?

Medium
37

A vulnerability scanner reports a vulnerability with a CVSS score of 9.8. What does this score indicate?

Medium
38

Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?

Easy
39

An organization's security team wants to validate that its incident response plan works as documented before a real breach occurs. The team needs to exercise communication paths, decision-making, and coordination among technical staff, legal, and public relations without touching production systems. Which of the following is the MOST appropriate exercise type?

Easy
40

An organization wants to ensure that its web application is secure by analyzing the source code for vulnerabilities without executing the code. Which type of testing is most appropriate?

Hard
41

Which THREE of the following are valid types of penetration testing based on the level of knowledge provided to the tester?

Hard
42

A security team is reviewing application security and needs to analyze source code without executing the application. Which technique should they use?

Medium
43

An organization is planning an external audit for SOC 2 Type II compliance. Which TWO of the following are true about this type of audit?

Medium
44

A security manager is planning a penetration test and needs to ensure proper rules of engagement are established. Which TWO of the following are essential components of the rules of engagement?

Medium
45

During a penetration testing engagement, which TWO of the following are essential components of the rules of engagement document?

Medium
46

A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?

Hard
47

During a penetration test, the tester successfully gains access to a server and then attempts to move laterally to other systems. This phase is known as:

Hard
48

A company is preparing for an external audit to comply with PCI DSS. Which type of auditor is typically required to perform this assessment?

Medium
49

An organization is preparing for an ISO 27001 certification audit. The audit will be performed by an external body. This type of audit is classified as:

Medium
50

A developer uses a tool that analyzes source code for potential security flaws without executing the program. This is an example of:

Medium
51

An organization is selecting security metrics to report to the board. Which THREE metrics would best demonstrate the effectiveness of the vulnerability management program?

Medium
52

An organization wants to test its web application for vulnerabilities by running the application and probing it with malicious inputs. Which tool is BEST suited for this purpose?

Medium
53

A company's security team uses a tool that instruments the application at runtime to monitor and block attacks. This is an example of:

Hard

Frequently asked questions

What does the Security Assessment and Testing domain cover on the CISSP exam?
Be able to match a stated goal to the right assessment type or tool category, especially scan versus exploit and static versus dynamic analysis. The single most important thing: read whether the scenario requires exploiting a vulnerability or only identifying it.
How many questions are in this domain?
This page lists all 53 Security Assessment and Testing questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Assessment and Testing questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp assessment testing Practice Questions