Courseiva

CCNA Security Assessment and Testing Questions

53 questions · Security Assessment and Testing · All types, answers revealed

1
Multi-Selecthard

A security team is selecting tools for code review. Which THREE of the following are characteristics of Static Application Security Testing (SAST) tools?

Select 3 answers
A.They require access to the source code
B.They are typically used after deployment
C.They can be integrated into the CI/CD pipeline
D.They analyze the application while it is running
E.They identify vulnerabilities early in the software development lifecycle
AnswersA, C, E

Static Application Security Testing (SAST) tools operate by analyzing an application's source code, bytecode, or binary code without actually executing the program. This direct access to the underlying code allows SAST to identify potential vulnerabilities such as buffer overflows, SQL injection flaws, and cross-site scripting (XSS) by examining code patterns and data flow paths. Without this direct access, SAST cannot perform its core function of static analysis, making it a fundamental requirement for its operation.

Why this answer

SAST tools analyze source code, bytecode, or binary code without executing the application. They require access to the source code to perform static analysis, scanning for security flaws such as injection vulnerabilities, buffer overflows, and insecure cryptographic implementations. This allows developers to identify and fix vulnerabilities early in the development lifecycle, before the code is compiled or deployed.

Exam trap

The trap here is confusing SAST with DAST: candidates often select 'analyze while running' (Option D) because they think 'static' means 'after deployment' or 'during runtime', but SAST is static (non-executing) and DAST is dynamic (executing).

2
MCQeasy

Which type of SOC report provides a public summary of an organization's controls over security, availability, and confidentiality?

A.SOC 2 Type II
B.SOC 1
C.SOC 2 Type I
D.SOC 3
AnswerD

SOC 3 reports are general-use reports that provide a public summary of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy (Trust Services Criteria). Unlike SOC 2 reports, SOC 3 reports do not contain the detailed description of controls or test results, making them suitable for public distribution, marketing, and demonstrating commitment to security without revealing sensitive operational details.

Why this answer

SOC 3 reports are designed for public distribution and summarize the findings of a SOC 2 engagement.

3
Multi-Selecthard

Which THREE of the following are common key performance indicators (KPIs) used in security assessment and testing?

Select 3 answers
A.Mean time to remediate critical vulnerabilities
B.Patch compliance percentage
C.Number of employees trained on security awareness
D.Open vulnerability count by severity
E.Number of help desk tickets
AnswersA, B, D

This is a crucial Key Performance Indicator (KPI) because it directly measures the efficiency and effectiveness of an organization's vulnerability management program. A shorter mean time indicates a robust process for identifying, prioritizing, and mitigating the most severe security flaws, thereby reducing the window of opportunity for potential exploitation. This metric reflects the operational responsiveness to high-risk findings.

Why this answer

Mean time to remediate critical vulnerabilities (A) is a core security-assessment KPI because it measures how quickly the organization closes high-risk findings, directly reflecting the effectiveness of its vulnerability management process. Patch compliance percentage (B) is also a standard KPI, quantifying the proportion of systems that have current patches applied and thus indicating exposure to known exploits. Open vulnerability count by severity (D) is a common KPI that tracks the outstanding backlog of vulnerabilities grouped by critical, high, medium, and low, giving a snapshot of residual risk and remediation workload.

The other options are not typical security-assessment KPIs: the number of employees trained on security awareness (C) is a training/awareness metric rather than a measure of assessment or testing outcomes, and the number of help desk tickets (E) is an IT service management volume metric unrelated to security testing performance.

Exam trap

CISSP often tests the distinction between security assessment KPIs and general operational metrics; candidates may include training or help desk tickets, but those are not direct measures of assessment and testing effectiveness.

4
MCQmedium

An organization requires a security assessment that evaluates controls against a specific standard and results in a formal report. The organization is not required to exploit vulnerabilities. Which type of assessment is this?

A.Security audit
B.Vulnerability assessment
C.Penetration test
D.Security review
AnswerA

A security audit is a systematic, independent examination of an organization's information system controls to determine whether they are operating effectively and in compliance with established criteria, such as regulatory requirements, industry standards, or internal policies. It is a formal, evidence-based process culminating in a comprehensive report detailing findings, recommendations, and an overall assessment of the security posture relative to the audit scope. This process is crucial for demonstrating due diligence and meeting governance objectives.

Why this answer

A security audit is a formal, independent evaluation of controls against a predefined standard (e.g., ISO 27001, PCI DSS) that produces a formal report. Unlike other assessments, it does not require exploiting vulnerabilities; it focuses on verifying compliance through evidence collection and testing. This matches the question's requirement for a standard-based evaluation with a formal report and no exploitation.

Exam trap

The trap here is that candidates confuse a vulnerability assessment (which also does not exploit vulnerabilities) with a security audit, but the key differentiator is that an audit evaluates controls against a specific standard and produces a formal report, while a vulnerability assessment only identifies technical weaknesses without a compliance framework.

How to eliminate wrong answers

Option B is wrong because a vulnerability assessment identifies and lists vulnerabilities (e.g., missing patches, misconfigurations) using automated tools like Nessus or OpenVAS, but it does not evaluate controls against a specific standard or produce a formal compliance report. Option C is wrong because a penetration test actively exploits vulnerabilities to gain unauthorized access, which contradicts the requirement that the organization is not required to exploit vulnerabilities. Option D is wrong because a security review is typically an informal, internal evaluation (e.g., peer review of a design or configuration) that does not follow a specific standard or produce a formal, independent report.

5
Multi-Selecthard

A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?

Select 2 answers
A.Simplifies compliance with log retention requirements
B.Enables correlation of events across systems
C.Eliminates the need for log retention policies
D.Reduces the volume of logs generated
E.Automatically patches vulnerabilities
AnswersA, B

Centralized log management consolidates logs from disparate sources into a single repository, which significantly streamlines the process of applying uniform retention policies. This approach ensures data integrity and facilitates audit readiness for various regulatory compliance mandates, such as HIPAA, PCI DSS, or GDPR. Instead of managing retention across numerous individual systems, administrators can enforce policies consistently from a central point, simplifying evidence collection during audits and demonstrating adherence to legal requirements.

Why this answer

Option A is correct because a centralized log management platform applies uniform retention settings and storage policies across all ingested sources, which directly simplifies demonstrating compliance with regulatory log retention requirements (e.g., PCI DSS 10.7, HIPAA, SOX). Option B is correct because aggregating logs from multiple systems into one platform allows the SIEM/log manager to correlate events across hosts, applications, and network devices, enabling detection of multi-stage or distributed attacks that would be invisible in isolated logs. Option C is wrong because centralization does not remove the need for retention policies; it actually requires well-defined retention rules to manage storage and compliance.

Option D is wrong because centralization aggregates and stores logs, typically increasing rather than reducing total log volume, though it may improve analysis efficiency. Option E is wrong because log management platforms collect and analyze logs; they do not automatically patch vulnerabilities, which is the role of patch management or vulnerability management tools.

Exam trap

CISSP often tests the misconception that centralizing logs automatically reduces log volume or eliminates policy needs, when in fact it increases the importance of retention policies and does not change source log generation.

6
MCQmedium

Which vulnerability scoring system provides a standardized severity rating for vulnerabilities based on exploitability and impact metrics?

A.NVD
B.CVE
C.CVSS
D.CWE
AnswerC

The Common Vulnerability Scoring System (CVSS) is an open industry standard designed to provide a qualitative and quantitative method for assessing the severity of software vulnerabilities. It generates a numerical score, ranging from 0.0 to 10.0, based on various metrics like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. This standardized scoring allows organizations to objectively prioritize vulnerability remediation efforts based on a consistent, globally recognized framework.

Why this answer

The Common Vulnerability Scoring System (CVSS) provides a standardized, quantitative framework for rating the severity of security vulnerabilities. It calculates a score from 0.0 to 10.0 based on exploitability metrics (e.g., attack vector, complexity, privileges required) and impact metrics (e.g., confidentiality, integrity, availability), enabling organizations to prioritize remediation efforts consistently.

Exam trap

ISC2 often tests the distinction between a vulnerability database (NVD), an identifier system (CVE), a weakness taxonomy (CWE), and a scoring system (CVSS), so the trap is confusing the repository or identifier with the actual scoring methodology.

How to eliminate wrong answers

Option A is wrong because NVD (National Vulnerability Database) is a repository that stores vulnerability data and enriches it with CVSS scores, but it is not a scoring system itself. Option B is wrong because CVE (Common Vulnerabilities and Exposures) is a dictionary of unique identifiers for publicly known vulnerabilities, not a severity rating system. Option D is wrong because CWE (Common Weakness Enumeration) is a taxonomy of software weakness types, not a scoring system for vulnerability severity.

7
MCQeasy

Which of the following is a key element of the rules of engagement for a penetration test?

A.Emergency stop criteria
B.The tester's compensation
C.The tester's background check
D.The number of vulnerabilities to find
AnswerA

Rules of Engagement (RoE) are critical for defining the scope, boundaries, and acceptable methods of a penetration test or security assessment. Emergency stop criteria are a fundamental element within the RoE, explicitly outlining specific conditions or thresholds that, if met, necessitate an immediate cessation of testing activities. These criteria are crucial for preventing unintended service disruptions, data corruption, or irreversible damage to the target systems, ensuring the integrity and availability of the client's environment are maintained even during aggressive testing. They often include triggers like critical system crashes, excessive network latency, or detection of unauthorized access to non-target systems.

Why this answer

Emergency stop criteria is correct because rules of engagement (RoE) must define the conditions under which testing halts immediately — for example, discovery of a live production outage, unintended data exfiltration, or a critical system failure — so the client can protect business continuity and the tester has legal cover to stop. RoE is a governance document that scopes authorization, timing, targets, and abort conditions, and the stop criteria are its most safety-critical clause. Without explicit halt conditions, a tester could inadvertently cause an outage with no agreed protocol for disengagement.

Exam trap

CISSP often tests the distinction between contractual/commercial terms and operational security governance, so the trap is selecting a business or HR item (compensation, background check) as if it belonged in the RoE.

How to eliminate wrong answers

Option B is wrong because tester compensation is a contractual/commercial term handled in the statement of work or master services agreement, not a technical or operational element of the rules of engagement. Option C is wrong because the tester's background check is a pre-engagement personnel-vetting step performed before authorization, not a clause within the RoE document itself. Option D is wrong because the number of vulnerabilities to find is an arbitrary, non-deterministic metric — RoE defines scope and constraints, not a quota of findings, and promising a count would incentivize fabricated or inflated results.

8
MCQhard

A company wants to ensure its internal web application is free from security flaws during development. Which testing approach analyzes source code without executing the program?

A.IAST
B.RASP
C.DAST
D.SAST
AnswerD

SAST (Static Application Security Testing) directly examines the application's source code, bytecode, or binary code without executing it, identifying potential security vulnerabilities like SQL injection or cross-site scripting. This "white-box" approach is ideal for finding flaws early in the development lifecycle, before the application is even compiled or deployed, making it highly effective for proactive security.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binaries without executing the program, which is exactly what the question describes. It is integrated into the IDE or CI/CD pipeline to catch flaws like SQL injection, XSS, and hardcoded secrets early in the SDLC, shifting security left.

Exam trap

CISSP often tests the SAST vs DAST vs IAST vs RASP taxonomy — candidates pick DAST because it sounds like 'testing the app,' forgetting that SAST is the only one that analyzes source code without executing it.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) instruments a running application and analyzes behavior during execution, typically via an agent — it requires a running app and often a DAST-style scan or test suite. Option B is wrong because RASP (Runtime Application Self-Protection) is a runtime protection mechanism embedded in the app that detects and blocks attacks in production; it is not a source-code analysis technique. Option C is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside (black-box) by sending malicious inputs and observing responses — it does not read source code.

9
MCQmedium

A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?

A.Storage capacity
B.Incident response needs
C.Regulatory requirements
D.Log volume
AnswerC

Regulatory requirements are the primary driver for log retention policies because various compliance frameworks, such as HIPAA, PCI DSS, GDPR, and SOX, explicitly mandate specific types of logs and their minimum retention periods. These mandates ensure accountability, provide an audit trail, and support legal defensibility, with non-compliance leading to severe penalties, fines, and reputational damage. Organizations must align their log retention strategies directly with these external obligations.

Why this answer

Regulatory compliance frameworks (e.g., PCI DSS, HIPAA, SOX, GDPR) explicitly mandate minimum log retention periods (e.g., PCI DSS Requirement 10.7 requires at least one year of logs, with three months immediately accessible). Storage capacity, incident response needs, and log volume are operational considerations that may influence implementation but do not override the legal or contractual obligation to retain logs for a specified duration. The primary factor is the regulatory requirement itself, as failure to comply can result in fines, legal liability, or loss of certification.

Exam trap

The trap here is that candidates often confuse operational factors (storage capacity, log volume) with the primary driver (regulatory requirements), mistakenly thinking that if storage is limited, the retention period can be shortened—but compliance mandates are non-negotiable and must be met regardless of infrastructure constraints.

How to eliminate wrong answers

Option A is wrong because storage capacity is a resource constraint that may force log rotation or archiving, but it does not define the retention period; organizations must provision sufficient storage to meet regulatory mandates. Option B is wrong because incident response needs may require retaining logs beyond the standard period for forensic analysis, but they do not set the baseline retention period; the baseline is driven by compliance, not by the timing of incidents. Option D is wrong because log volume affects how logs are stored and rotated (e.g., log rotation policies based on size), but the retention duration is a time-based requirement set by regulations, not a function of how many logs are generated.

10
MCQeasy

Which of the following is a key component of the rules of engagement for a penetration test?

A.Exploitation techniques to use
B.Emergency stop criteria
C.CVSS score of vulnerabilities
D.Number of vulnerabilities found
AnswerB

Emergency stop criteria are a critical component of the Rules of Engagement (RoE) because they explicitly define the conditions under which an engagement must be immediately halted to prevent unintended harm, legal issues, or excessive risk. These criteria ensure that testing can be safely terminated if unexpected system instability, unauthorized access to sensitive data, or other critical incidents occur, thereby protecting the target environment and the testing team. Establishing these clear boundaries is fundamental to responsible and controlled security assessments.

Why this answer

Emergency stop criteria are a core element of the rules of engagement (RoE) for a penetration test because they define the conditions under which testing must immediately halt — for example, if production availability is threatened or a critical system is destabilized. RoE documents scope, timing, authorized techniques, communication channels, and stop conditions agreed upon by the client and tester.

Exam trap

CISSP often tests the confusion between RoE (pre-engagement boundaries and stop conditions) and post-engagement outputs (CVSS scores, vulnerability counts), so candidates who pick a metric or technique miss the definition of RoE.

How to eliminate wrong answers

Option A is wrong because specific exploitation techniques are typically described in the testing methodology or scope, not as a defining component of the RoE — and RoE focuses on boundaries and constraints rather than a menu of exploits. Option C is wrong because CVSS scores are assigned to discovered vulnerabilities during or after testing; they are an output, not an RoE input. Option D is wrong because the number of vulnerabilities found is a result metric, not a component of the rules of engagement.

11
MCQmedium

A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:

A.Security baseline
B.Key Goal Indicator (KGI)
C.Key Performance Indicator (KPI)
D.Key Risk Indicator (KRI)
AnswerC

A Key Performance Indicator (KPI) is a quantifiable metric used to evaluate the success of a particular activity, process, or project against predefined objectives. Mean time to remediate (MTTR) is an excellent example of a KPI because it directly measures the efficiency and effectiveness of the incident response and vulnerability management processes. Tracking MTTR allows security managers to assess operational performance, identify bottlenecks, and drive continuous improvement in their remediation efforts.

Why this answer

Mean time to remediate (MTTR) for critical vulnerabilities measures how efficiently the security team is performing remediation, making it a Key Performance Indicator (KPI). KPIs track the performance of processes and activities against operational targets.

Exam trap

CISSP often tests the distinction between KPI (process performance), KGI (goal achievement), and KRI (risk exposure) — candidates frequently confuse KPI with KRI because both involve metrics.

How to eliminate wrong answers

Option A is wrong because a security baseline is a documented minimum set of controls or configurations, not a performance measurement. Option B is wrong because a Key Goal Indicator (KGI) measures whether high-level business goals have been achieved (e.g., 'reduce breach risk by 30%'), not the speed of an operational process. Option D is wrong because a Key Risk Indicator (KRI) is a forward-looking metric that signals increasing risk exposure (e.g., number of unpatched critical systems), whereas MTTR measures past remediation performance.

12
Multi-Selecthard

An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?

Select 3 answers
A.Reviewing logs only after a security incident
B.Log retention policies that comply with legal and regulatory requirements
C.Storing logs in plaintext without access controls
D.Regularly scheduled review of logs for anomalies
E.Centralized log management for aggregation and correlation
AnswersB, D, E

Establishing log retention policies that strictly comply with all applicable legal and regulatory requirements is fundamental for maintaining an organization's security posture and legal standing. These policies ensure that critical audit trails are preserved for forensic investigations, e-discovery, and regulatory audits, demonstrating due diligence and accountability. Proper retention periods prevent premature deletion of evidence while also managing storage costs and data privacy obligations.

Why this answer

Option B is correct because log retention policies must satisfy legal, regulatory, and contractual requirements (e.g., GDPR, HIPAA, PCI DSS, SOX), ensuring logs are kept for the mandated period and disposed of securely afterward. Option D is correct because effective log review requires regularly scheduled reviews, not just reactive ones, so that anomalies, trends, and indicators of compromise can be detected proactively before they escalate. Option E is correct because centralized log management (e.g., via a SIEM or syslog server) aggregates logs from disparate sources, enabling correlation across systems and time synchronization for accurate event reconstruction.

Option A is not appropriate because reviewing logs only after an incident is reactive and misses ongoing threats, while option C is wrong because storing logs in plaintext without access controls exposes sensitive data and violates integrity and confidentiality requirements.

Exam trap

The trap here is that candidates may think reviewing logs only after an incident is sufficient, but the CISSP emphasizes proactive, continuous monitoring as a key security control, not just reactive forensics.

13
MCQeasy

An organization wants to test its security controls by simulating an attack where the tester has no prior knowledge of the internal network. This is known as a:

A.Grey box test
B.White box test
C.Red team exercise
D.Black box test
AnswerD

A black box test simulates an external attacker with absolutely no prior knowledge of the target system's internal architecture, network topology, or source code. Testers approach the system purely from an outsider's perspective, relying on public information, reconnaissance, and common attack methodologies to discover vulnerabilities. This method directly assesses how well an organization's external defenses would withstand an attack from an unknown, unprivileged adversary.

Why this answer

A black box test (D) is correct because the tester has no prior knowledge of the internal network, simulating an external attacker with zero inside information. This approach evaluates the security controls from an unprivileged, external perspective, relying solely on publicly available information and active reconnaissance. It is the purest form of adversarial simulation for testing perimeter defenses and detection capabilities.

Exam trap

The trap here is confusing the testing methodology (black/grey/white box) with the team structure (red team exercise), leading candidates to select 'Red team exercise' because it sounds like an attack simulation, but the question explicitly defines the knowledge level, not the team composition.

How to eliminate wrong answers

Option A is wrong because a grey box test involves partial knowledge of the internal network, such as network diagrams or credentials, which contradicts the 'no prior knowledge' requirement. Option B is wrong because a white box test provides full knowledge of the internal network, including source code, architecture, and credentials, which is the opposite of the described scenario. Option C is wrong because a red team exercise is a broader, goal-oriented adversarial simulation that may use black, grey, or white box methodologies; the question specifically asks for the type of test based on knowledge level, not the team structure.

14
Multi-Selectmedium

A company is planning to conduct a penetration test. Which THREE of the following should be included in the rules of engagement?

Select 3 answers
A.The tester's personal contact information
B.Emergency stop criteria
C.Definition of the scope (systems to be tested)
D.Written authorization from management
E.Specific vulnerabilities to be exploited
AnswersB, C, D

Emergency stop criteria are crucial elements within the Rules of Engagement, defining specific conditions under which the penetration test must be immediately halted. These criteria typically include scenarios such as causing a critical system outage, corrupting production data, triggering an organization-wide incident response, or exceeding predefined resource utilization thresholds. Establishing these clear boundaries ensures that the testing activities do not inflict unacceptable damage or operational disruption to the target environment.

Why this answer

Emergency stop criteria define the conditions under which the penetration test must be immediately halted, such as causing a production system outage or detecting unauthorized data access. This is a critical component of the rules of engagement (RoE) to ensure the test does not cause unacceptable business impact, aligning with the principle of minimizing risk during security assessments.

Exam trap

The trap here is that candidates often confuse the rules of engagement with the test plan or methodology, mistakenly including operational details like specific vulnerabilities or personal contact information, when the RoE is strictly about boundaries, authorization, and safety constraints.

15
MCQeasy

A company must comply with a regulation requiring a formal, independent assessment of its security controls against a standard. Which type of assessment is MOST appropriate?

A.Penetration test
B.Security audit
C.Security review
D.Vulnerability assessment
AnswerB

A security audit is a formal, independent, and systematic examination of an organization's security controls, processes, and policies against a specific set of criteria, such as regulatory requirements or industry standards. It involves evidence collection, analysis, and reporting to determine the extent of compliance and the effectiveness of controls. This structured, evidence-based approach, conducted by independent parties, is precisely what a regulation requiring a formal comparison of controls to a standard demands.

Why this answer

A security audit is the most appropriate assessment because it is a formal, independent evaluation of an organization's security controls against a predefined standard (e.g., ISO 27001, NIST SP 800-53). Unlike other assessments, an audit is conducted by an independent third party or internal audit function, providing objective evidence of compliance with regulatory requirements.

Exam trap

The trap here is that candidates confuse a security audit with a penetration test or vulnerability assessment, mistakenly thinking that technical exploitation is required for compliance, when the regulation specifically demands an independent evaluation against a standard, not a technical attack simulation.

How to eliminate wrong answers

Option A is wrong because a penetration test is an authorized simulated attack to exploit vulnerabilities, not a formal assessment of controls against a standard; it focuses on identifying exploitable weaknesses rather than compliance. Option C is wrong because a security review is typically an informal, internal evaluation (e.g., peer review or design review) that lacks the independence and formal structure required for regulatory compliance. Option D is wrong because a vulnerability assessment is an automated or manual scan to identify and list vulnerabilities (e.g., missing patches, misconfigurations), but it does not evaluate controls against a specific standard or provide an independent compliance opinion.

16
MCQhard

A security analyst is reviewing logs from multiple systems and needs to ensure that logs are tamper-proof and available for incident investigation. Which of the following is the BEST approach?

A.Use a cloud storage bucket with public read access
B.Store logs locally on each system with restricted permissions
C.Encrypt logs at the source and send via email to the security team
D.Centralize logs to a syslog server with cryptographic hashing and append-only access
AnswerD

Centralizing logs to a dedicated syslog server significantly enhances security by providing a single, hardened repository for all audit data, making it easier to monitor and analyze. Cryptographic hashing ensures the integrity of each log entry, detecting any unauthorized modifications or tampering attempts after creation. Combined with append-only access, which prevents deletion or alteration of historical records, this approach provides a robust, forensically sound audit trail critical for incident response and compliance.

Why this answer

Option D is correct because it combines three essential log-security controls: centralization (so logs survive compromise of individual hosts), cryptographic hashing (which provides integrity verification and detects tampering), and append-only access (which prevents attackers or insiders from deleting or altering existing records). Centralizing to a syslog server also supports availability for incident investigation, since logs are not lost if a source system is wiped. Together, these controls directly satisfy the requirement for tamper-proof, investigation-ready logs.

Exam trap

CISSP often tests the misconception that encryption alone equals tamper-proofing, when integrity (hashing/signing) and append-only controls are what actually detect and prevent log modification.

How to eliminate wrong answers

Option A is wrong because a publicly readable cloud bucket exposes sensitive log data to anyone on the internet and provides no integrity protection, so logs could be read, copied, or replaced without detection. Option B is wrong because local storage with restricted permissions still leaves logs vulnerable to a compromised host, privileged insiders, ransomware, or disk failure, and it prevents correlation across systems during an investigation. Option C is wrong because email is not a reliable or secure log transport: it lacks integrity guarantees, can be intercepted or altered in transit, has mailbox size limits, and provides no centralized, tamper-evident repository for forensic review.

17
Multi-Selectmedium

Which TWO of the following are characteristics of a SOC 2 Type II report?

Select 2 answers
A.Covers the design and operating effectiveness of controls over a period of time
B.Is a public summary report available to anyone
C.Includes trust service criteria such as security, availability, and confidentiality
D.Focuses only on financial reporting controls
E.Evaluates controls at a single point in time
AnswersA, C

A SOC 2 Type II report provides an opinion on the suitability of the design of controls and their operating effectiveness throughout a specified reporting period, typically 6-12 months. This extended observation period offers a higher level of assurance regarding the consistent application and performance of a service organization's system and controls. It demonstrates sustained adherence to the Trust Service Criteria, which is crucial for user entities relying on these services.

Why this answer

Option A is correct because a SOC 2 Type II report specifically tests both the design and the operating effectiveness of controls throughout a defined review period (typically 3–12 months), unlike a Type I report which only assesses design at a point in time. Option C is correct because SOC 2 engagements are structured around the AICPA Trust Services Criteria, which include security (required) plus availability, processing integrity, confidentiality, and privacy as optional categories. Option B is incorrect because SOC 2 reports are restricted-use reports distributed under NDA to management, customers, and auditors—not public documents (that role belongs to SOC 3).

Option D is incorrect because financial reporting controls are the focus of SOC 1 (SSAE 18/ISAE 3402), not SOC 2. Option E is incorrect because point-in-time evaluation describes a SOC 2 Type I report, whereas Type II covers a period.

Exam trap

CISSP often tests the distinction between SOC 2 Type I and Type II, and between SOC 2 and SOC 3 reports, causing candidates to confuse point-in-time vs. period coverage or public vs. restricted distribution.

18
MCQhard

During a penetration test, the tester gains initial access to a server and then attempts to pivot to other systems. Which phase of the penetration testing process does this represent?

A.Post-exploitation/lateral movement
B.Reconnaissance
C.Exploitation
D.Reporting
AnswerA

After gaining initial access, the penetration tester enters the post-exploitation phase. This involves actions like privilege escalation on the compromised system, establishing persistence to maintain access, and then pivoting to other systems within the network. Lateral movement aims to expand the tester's control and reach additional valuable assets beyond the initial foothold, demonstrating the potential impact of a breach.

Why this answer

After gaining initial access, the penetration tester attempts to pivot to other systems, which is part of post-exploitation and specifically lateral movement. This phase involves expanding access, escalating privileges, and moving laterally within the network to compromise additional targets.

Exam trap

CISSP often tests the phases of penetration testing, and candidates may confuse exploitation with post-exploitation; the key is that lateral movement occurs after initial access, so it is post-exploitation.

How to eliminate wrong answers

Option B is wrong because reconnaissance is the initial phase of gathering information about the target before any exploitation, not after gaining access. Option C is wrong because exploitation is the phase where the tester actually gains initial access by exploiting a vulnerability, which has already occurred. Option D is wrong because reporting is the final phase where findings are documented and presented, not the phase involving lateral movement.

19
Multi-Selecteasy

Which TWO of the following are benefits of authenticated vulnerability scanning compared to unauthenticated scanning?

Select 2 answers
A.Can detect vulnerabilities that require valid credentials to be seen
B.Reduces network traffic
C.Eliminates false positives entirely
D.Provides more accurate patch-level information
E.Does not require network access
AnswersA, D

Authenticated scans operate with valid credentials, allowing them to access the internal configuration, file systems, and running processes of a target system. This deep access enables the detection of vulnerabilities that are only visible post-authentication, such as misconfigurations in internal services, insecure file permissions, or unpatched software versions that an unauthenticated scan might miss entirely.

Why this answer

Option A is correct because authenticated scanning logs into the target host with valid credentials, allowing the scanner to inspect local files, registry keys, installed packages, and configuration settings that are invisible to an unauthenticated scan, thereby detecting vulnerabilities that require credentials to be seen. Option D is correct because credentialed access lets the scanner read exact software versions, patch levels, and update history directly from the host, yielding more accurate patch-level information than remote banner grabbing or version inference. Option B is not correct because authenticated scans typically generate more traffic, not less, since they perform deeper enumeration and local checks.

Option C is not correct because no scanning method eliminates false positives entirely; authentication reduces but does not remove them. Option E is not correct because authenticated scans still require network access to reach and log into the target host.

Exam trap

CISSP often tests the misconception that authenticated scanning is 'quieter' or 'faster' — in reality it is deeper and heavier, and the exam expects you to recognize that its primary benefits are visibility and accuracy, not traffic reduction.

20
MCQeasy

A security analyst is asked to identify vulnerabilities in a web application without attempting to exploit them. Which type of assessment is being performed?

A.Security review
B.Vulnerability assessment
C.Security audit
D.Penetration test
AnswerB

A vulnerability assessment systematically scans systems, applications, and networks for known security weaknesses, configuration errors, and missing patches. It utilizes automated tools and manual analysis to identify potential flaws without attempting to exploit them. The primary goal is to provide a prioritized list of vulnerabilities that could be exploited, enabling organizations to proactively address risks before they are leveraged by attackers.

Why this answer

A vulnerability assessment is a systematic review of security weaknesses in a system or application, but it does not involve actively exploiting those weaknesses. The question specifies that the analyst is asked to identify vulnerabilities without attempting to exploit them, which directly matches the definition of a vulnerability assessment. This type of assessment typically uses automated scanners (e.g., Nessus, OpenVAS) and manual checks to enumerate potential vulnerabilities, such as missing patches or misconfigurations, without moving to the exploitation phase.

Exam trap

The trap here is that candidates often confuse vulnerability assessment with penetration testing, assuming that any active testing must include exploitation, but the CISSP exam emphasizes the distinction that vulnerability assessment stops at identification, while penetration testing includes exploitation.

How to eliminate wrong answers

Option A is wrong because a security review is a broad, often high-level evaluation of security policies, procedures, and controls, not a focused technical scan for specific vulnerabilities in a web application. Option C is wrong because a security audit is a formal, compliance-driven examination against a defined standard (e.g., ISO 27001, PCI DSS), which may include vulnerability identification but is not limited to it and often involves verifying controls rather than just scanning for weaknesses. Option D is wrong because a penetration test actively exploits vulnerabilities to determine the extent of compromise, which contradicts the question's condition of not attempting to exploit them.

21
MCQhard

Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?

A.SOC 2 Type II
B.SOC 3
C.SOC 1 Type II
D.SOC 2 Type I
AnswerB

A SOC 3 report is specifically designed for general public use, offering a high-level summary of a service organization's internal controls related to the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Unlike SOC 2 reports, it omits the detailed description of controls and test results, making it suitable for marketing purposes or posting on a website without revealing sensitive operational details. Its primary purpose is public assurance.

Why this answer

SOC 3 reports are designed for public distribution and provide a high-level summary of an organization's controls related to security, availability, confidentiality, integrity, and privacy (the Trust Services Criteria). Unlike SOC 2 reports, SOC 3 reports do not include detailed testing results, control descriptions, or the auditor's opinion on control effectiveness, making them suitable for marketing or public disclosure.

Exam trap

The trap here is that candidates confuse SOC 2 Type II (which includes detailed testing results) with SOC 3, or assume that SOC 2 Type I (point-in-time) is a public summary, when in fact SOC 3 is the only report designed for public distribution without detailed testing results.

How to eliminate wrong answers

Option A is wrong because SOC 2 Type II reports include detailed testing results over a period of time, including the auditor's opinion on the effectiveness of controls, which contradicts the question's requirement for a public summary without detailed testing results. Option C is wrong because SOC 1 Type II reports focus on controls relevant to financial reporting (under SSAE 18) and are restricted to user entities and their auditors, not public summaries, and they include detailed testing results. Option D is wrong because SOC 2 Type I reports, while covering the same Trust Services Criteria, describe controls at a single point in time and include detailed control descriptions and auditor opinions, not a public summary without testing results.

22
MCQeasy

A company hires a third party to perform an assessment where the testers are given no prior knowledge of the internal network. This type of penetration test is known as:

A.Black box
B.White box
C.Grey box
D.Internal test
AnswerA

Black box testing simulates an external attacker with no prior knowledge of the target system's internal structure, network architecture, or source code. The assessor approaches the system as an unprivileged outsider, attempting to discover vulnerabilities through publicly available information and external reconnaissance. This method effectively evaluates an organization's perimeter defenses and its ability to withstand real-world, unknown threats, making it ideal for a third-party assessment where initial knowledge is withheld.

Why this answer

A black box penetration test simulates an external attacker with no prior knowledge of the target environment. The testers are given no credentials, network diagrams, or internal details, forcing them to perform reconnaissance and exploitation from an outsider's perspective. This aligns directly with the scenario where the third party has 'no prior knowledge of the internal network.'

Exam trap

The trap here is confusing the test's knowledge level (black, white, grey) with the test's origin (internal vs. external), leading candidates to incorrectly select 'Internal test' because they associate 'no prior knowledge' with an external perspective, but the question explicitly asks for the type based on knowledge, not location.

How to eliminate wrong answers

Option B is wrong because a white box test provides testers with full knowledge of the internal network, including credentials, source code, and architecture diagrams, which contradicts the 'no prior knowledge' condition. Option C is wrong because a grey box test offers limited knowledge, such as user-level credentials or partial network maps, not zero prior knowledge. Option D is wrong because an internal test is defined by the test's origin (inside the network perimeter), not by the level of knowledge; internal tests can be black, white, or grey box, and the question specifically describes the knowledge level, not the test location.

23
MCQmedium

During a penetration test, the tester has obtained initial access and is now trying to move laterally to other systems. Which phase of the penetration testing process does this represent?

A.Reconnaissance
B.Reporting
C.Post-exploitation/lateral movement
D.Exploitation
AnswerC

Post-exploitation begins immediately after initial access is successfully gained on a target system. This crucial phase focuses on maintaining access, escalating privileges within the compromised system, gathering sensitive information, and establishing persistence mechanisms. Lateral movement is a key component, involving techniques to pivot from the initial compromised host to other systems within the network, expanding the tester's foothold and access to additional resources to simulate a real-world breach.

Why this answer

The post-exploitation/lateral movement phase occurs after initial access is gained, where the tester uses compromised systems as pivot points to access other network segments, often leveraging tools like PsExec, WMI, or SMB relay to move across hosts. This phase is distinct from exploitation, which focuses on gaining the initial foothold, and reconnaissance, which occurs before any access is obtained.

Exam trap

The trap here is confusing 'exploitation' (gaining initial access) with 'post-exploitation/lateral movement' (using that access to move to other systems), as candidates often think any active attack step is 'exploitation' without recognizing the sequential phases of a penetration test.

How to eliminate wrong answers

Option A is wrong because reconnaissance is the initial information-gathering phase (e.g., DNS enumeration, port scanning) that occurs before any access is obtained, not after initial access. Option B is wrong because reporting is the final phase where findings are documented and presented to stakeholders, not during active lateral movement. Option D is wrong because exploitation is the phase where vulnerabilities are used to gain initial access (e.g., exploiting an SMB vulnerability), not the subsequent movement to other systems.

24
MCQeasy

An organization wants to identify vulnerabilities in their network without attempting to exploit them. Which type of security assessment should they perform?

A.Vulnerability assessment
B.Penetration test
C.Security audit
D.Security review
AnswerA

A vulnerability assessment systematically scans systems, networks, and applications to identify security weaknesses and misconfigurations. It uses automated tools and manual checks to detect known vulnerabilities, providing a prioritized list of potential risks without actively attempting to compromise the system. The goal is to inform remediation efforts by cataloging exposures and potential attack vectors, aligning precisely with the organization's desire to identify vulnerabilities without exploitation.

Why this answer

A vulnerability assessment is the correct choice because it is a systematic review of security weaknesses in a network or system that identifies vulnerabilities without actively exploiting them. This assessment typically uses automated scanning tools (e.g., Nessus, OpenVAS) to compare system configurations against known vulnerability databases (e.g., CVE, NVD) and reports potential issues, but does not attempt to gain unauthorized access or cause disruption.

Exam trap

The trap here is that candidates confuse a vulnerability assessment with a penetration test, assuming both involve exploitation, but the key differentiator is that a vulnerability assessment only identifies vulnerabilities, while a penetration test actively exploits them.

How to eliminate wrong answers

Option B is wrong because a penetration test (pentest) is an authorized simulated attack that actively attempts to exploit identified vulnerabilities to gain access or escalate privileges, which contradicts the requirement to not exploit them. Option C is wrong because a security audit is a formal, compliance-driven evaluation of an organization's adherence to policies, standards, or regulations (e.g., ISO 27001, PCI DSS) and does not focus specifically on identifying technical vulnerabilities in the network. Option D is wrong because a security review is a broad, often high-level examination of security controls, processes, or architecture, and it lacks the targeted, technical scanning and identification of specific vulnerabilities that a vulnerability assessment provides.

25
Multi-Selecteasy

Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?

Select 2 answers
A.Mean time to remediate critical vulnerabilities
B.Number of servers in the data center
C.Total IT budget
D.Patch compliance percentage
E.Number of employees in the security department
AnswersA, D

Mean time to remediate critical vulnerabilities is a crucial operational security metric, directly indicating the efficiency and effectiveness of an organization's vulnerability management program. It quantifies the average duration from the discovery of a critical vulnerability to its complete resolution, reflecting the organization's ability to mitigate high-risk threats promptly and reduce its attack surface. A lower mean time signifies a more robust and responsive security posture, directly impacting risk reduction.

Why this answer

Option A (Mean time to remediate critical vulnerabilities) is correct because it is a quantifiable security metric that measures how quickly the organization responds to and fixes critical vulnerabilities, directly reflecting the effectiveness of its vulnerability management process and serving as a meaningful KPI for security operations. Option D (Patch compliance percentage) is correct because it measures the proportion of systems that have required patches applied within policy timeframes, providing a measurable indicator of the organization's exposure to known exploits and the health of its patch management program. In contrast, option B (Number of servers in the data center) is an inventory or capacity figure that does not measure security performance or risk reduction.

Option C (Total IT budget) is a financial metric reflecting spending, not security effectiveness. Option E (Number of employees in the security department) is a staffing or headcount measure that indicates resource allocation but does not itself quantify security posture or outcomes.

Exam trap

CISSP often tests the difference between security metrics and general IT or business metrics, so candidates may mistakenly select operational counts like number of servers or budget as KPIs.

26
Multi-Selectmedium

A security analyst is setting up a vulnerability scanning program. Which TWO of the following are best practices for determining scanning frequency?

Select 2 answers
A.Scan once per year to minimize operational impact
B.Scan after significant changes to the infrastructure
C.Align scan frequency with the organization's risk appetite
D.Scan only when vulnerabilities are publicly disclosed
E.Use the same interval for all systems regardless of criticality
AnswersB, C

Significant infrastructure changes, such as deploying new systems, modifying network configurations, or updating major applications, frequently introduce new vulnerabilities or misconfigurations. Scanning immediately after these modifications ensures that any newly exposed attack surfaces or security flaws are identified and remediated before they can be exploited. This proactive approach minimizes the window of exposure created by system evolution and maintains a strong security posture.

Why this answer

Option B is correct because scanning after significant infrastructure changes (new hosts, patched services, reconfigurations, or new deployments) catches newly introduced vulnerabilities and misconfigurations before attackers can exploit them, which is a core tenet of continuous vulnerability management. Option C is correct because scanning frequency should be driven by the organization's risk appetite and tolerance, ensuring that high-value or high-risk assets are scanned more often while lower-risk systems may be scanned less frequently, balancing security coverage against operational cost. Option A is incorrect because an annual scan is far too infrequent to detect and remediate vulnerabilities before exploitation, and it ignores risk-based scheduling.

Option D is incorrect because relying only on public disclosure events is reactive and misses internally discovered or non-public vulnerabilities. Option E is incorrect because a uniform interval ignores asset criticality and exposure, contradicting risk-based vulnerability management.

Exam trap

Candidates often fall into the trap of choosing a static, one-size-fits-all interval (like Option E) or an overly conservative frequency to avoid performance degradation (like Option A). Best practices dictate a dynamic approach combining regular risk-aligned intervals with event-driven scans after major changes.

27
Multi-Selecthard

A security manager is designing a continuous monitoring program to satisfy ongoing authorization requirements. The program must detect unauthorized configuration changes to production servers, verify that security patches are applied within policy timeframes, and provide evidence for auditors. Which TWO of the following controls BEST support these objectives? (Choose two.)

Select 2 answers
A.A vulnerability scanner scheduled to run quarterly against all production servers with results emailed to the security team
B.Security information and event management (SIEM) correlation of change logs, patch deployment records, and FIM alerts with retention aligned to the audit period
C.A configuration management database (CMDB) updated manually by administrators when changes are made
D.Annual penetration testing of the production environment performed by an external firm
E.File integrity monitoring (FIM) that baselines critical system files and alerts on unauthorized modifications
AnswersB, E

A SIEM aggregates and correlates FIM alerts, patch deployment records, and change management logs, providing the centralized detection and evidence repository continuous monitoring requires. Retention aligned to the audit period ensures auditors can review historical events, and correlation surfaces changes that lack an approved change record.

Why this answer

Continuous monitoring requires automated, recurrent detection of change and patch state plus a durable evidence repository. File integrity monitoring detects unauthorized modifications against a baseline, while a SIEM correlates change, patch, and integrity data and retains it for audit review. Manual records and periodic scanning or testing cannot deliver the required continuous detection or evidence.

Exam trap

The trap here is equating periodic assessments such as quarterly scans or annual penetration tests with continuous monitoring.

28
MCQeasy

Which of the following is the primary purpose of a security audit?

A.To identify vulnerabilities in the network
B.To compare security controls against a defined standard
C.To perform an informal evaluation of security posture
D.To exploit vulnerabilities and demonstrate impact
AnswerB

The core function of a security audit is to systematically evaluate an organization's security posture by comparing its implemented security controls, policies, and procedures against a predetermined set of criteria. These criteria typically include industry best practices, regulatory requirements (e.g., GDPR, HIPAA), internal policies, or recognized security frameworks (e.g., ISO 27001, NIST CSF). This comparison determines the degree of compliance and identifies any deviations or gaps that need remediation.

Why this answer

A security audit's primary purpose is to systematically evaluate an organization's security controls against a predefined standard, such as ISO 27001, NIST SP 800-53, or PCI DSS. This comparison verifies compliance and identifies gaps, not merely vulnerabilities. Unlike a vulnerability assessment or penetration test, an audit focuses on adherence to criteria, not exploitation or informal review.

Exam trap

The trap here is confusing a security audit with a vulnerability assessment or penetration test, leading candidates to pick 'identify vulnerabilities' or 'exploit vulnerabilities' instead of recognizing the audit's formal, standards-based comparison purpose.

How to eliminate wrong answers

Option A is wrong because identifying vulnerabilities is the goal of a vulnerability assessment, not a security audit; an audit compares controls to a standard, not just finds weaknesses. Option C is wrong because a security audit is a formal, structured evaluation with defined criteria, not an informal assessment of posture. Option D is wrong because exploiting vulnerabilities to demonstrate impact is the objective of a penetration test, which is distinct from an audit's compliance-focused comparison.

29
MCQmedium

A security analyst is conducting a vulnerability scan of a web application. The scan identifies several vulnerabilities, but the analyst wants to minimize false positives. Which type of vulnerability scan would be most appropriate?

A.External scan
B.Passive scan
C.Authenticated scan
D.Unauthenticated scan
AnswerC

An authenticated scan is performed with valid user credentials, allowing the scanner to interact with the application as a legitimate, logged-in user. This approach provides a comprehensive view of vulnerabilities, including those in protected areas, authorization flaws, and business logic issues that are only accessible post-authentication. By simulating a real user, it significantly reduces false positives and offers a more accurate security posture assessment of the application's internal workings.

Why this answer

An authenticated scan uses valid credentials to log into the target system, allowing the scanner to access deeper configuration details and patch levels. This reduces false positives by distinguishing between vulnerabilities that are actually present and those that appear due to incomplete visibility, such as missing patches that are actually applied but not visible to an unauthenticated scanner.

Exam trap

The trap here is that candidates often assume an unauthenticated scan is more thorough because it tests from an attacker's perspective, but they miss that authenticated scans provide the internal visibility needed to eliminate false positives by verifying actual patch levels and configurations.

How to eliminate wrong answers

Option A is wrong because an external scan is performed from outside the network boundary and typically lacks internal context, leading to a higher rate of false positives due to incomplete visibility of internal services and configurations. Option B is wrong because a passive scan only monitors network traffic without actively probing systems, so it cannot verify the presence of vulnerabilities and often generates false positives from observed but unconfirmed behaviors. Option D is wrong because an unauthenticated scan does not use credentials, so it cannot access restricted areas of the application or system, resulting in many false positives from assumptions about missing patches or misconfigurations that may not actually exist.

30
MCQhard

During a SOC 2 audit, the auditor evaluates controls over a period of time to assess their operating effectiveness. Which type of SOC report is being performed?

A.SOC 2 Type II
B.SOC 1 Type I
C.SOC 3
D.SOC 2 Type I
AnswerA

A SOC 2 Type II report provides a comprehensive evaluation of a service organization's controls related to the Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy). Crucially, it assesses both the suitability of the design of these controls and their operating effectiveness over a defined period, typically 6-12 months. This report offers user entities a high level of assurance that controls were consistently applied and functioned as intended throughout the audit period.

Why this answer

A SOC 2 Type II report evaluates the operating effectiveness of controls over a period of time (typically 3–12 months), which is exactly what the auditor is doing here. Type II includes testing of control activities across the audit period, unlike Type I which only assesses design at a point in time.

Exam trap

CISSP often tests the distinction between Type I (point-in-time design) and Type II (operating effectiveness over time), and candidates confuse SOC 1/2/3 scope with report type.

How to eliminate wrong answers

Option B is wrong because SOC 1 Type I focuses on financial reporting controls and only at a point in time, not over a period. Option C is wrong because SOC 3 is a general-use report that provides only a seal/opinion without detailed control descriptions or period testing. Option D is wrong because SOC 2 Type I assesses control design at a single point in time, not operating effectiveness over a period.

31
MCQmedium

An organization is required to retain security logs for a minimum of one year to meet compliance regulations. Which practice is most directly related to this requirement?

A.Log review frequency
B.Log format standardization
C.Centralized log management
D.Log retention requirements
AnswerD

Log retention requirements explicitly define the mandatory duration for which security logs must be stored and maintained by an organization. These requirements are typically driven by legal obligations (e.g., GDPR, HIPAA), industry regulations (e.g., PCI DSS), compliance frameworks, or internal corporate policies for forensic investigations, auditing, and historical analysis. They directly address the "how long" aspect of log management, ensuring data availability for specified periods.

Why this answer

The requirement to retain security logs for a minimum of one year is directly about the duration logs must be stored. Option D, 'Log retention requirements,' is the practice that defines this storage duration, ensuring compliance with regulations such as PCI DSS or SOX. This is a policy-driven specification of how long logs are kept, not how they are reviewed, formatted, or collected.

Exam trap

The trap here is that candidates often confuse 'log retention requirements' with 'centralized log management,' thinking that centralization inherently includes retention, but retention is a separate policy that must be explicitly defined and configured regardless of where logs are stored.

How to eliminate wrong answers

Option A is wrong because log review frequency concerns how often logs are analyzed (e.g., daily or weekly), not how long they are stored; it addresses operational monitoring, not retention duration. Option B is wrong because log format standardization (e.g., syslog RFC 5424 or W3C Extended Log Format) ensures consistency for parsing and analysis, but does not dictate the retention period. Option C is wrong because centralized log management (e.g., using a SIEM like Splunk or ELK stack) aggregates logs from multiple sources for correlation and storage, but the retention period is a separate policy that defines how long logs are kept in that central repository.

32
MCQmedium

Which type of scanning provides the most comprehensive view of an organization's vulnerabilities by allowing the scanner to log into systems and access detailed configuration information?

A.External scan
B.Passive scan
C.Authenticated scan
D.Unauthenticated scan
AnswerC

An authenticated scan provides the most comprehensive view because it operates with legitimate user credentials, allowing it to log into target systems and inspect their internal configurations, patch levels, installed software, and user permissions directly. This privileged access enables the scanner to identify vulnerabilities that are only detectable from within the operating system or application, such as missing security updates, insecure registry settings, or weak file permissions, offering a true internal security posture assessment.

Why this answer

An authenticated scan (also called a credentialed scan) provides the scanner with valid credentials to log into target systems, allowing it to read installed software versions, registry keys, configuration files, and patch levels directly. This yields far more accurate and comprehensive vulnerability data than an unauthenticated scan, which can only probe from the outside and often produces false positives or misses local-only vulnerabilities.

Exam trap

The trap is equating 'external' with 'comprehensive' — candidates assume scanning from outside the network covers more, when in fact credentialed internal scanning provides deeper visibility into configurations and patches.

How to eliminate wrong answers

Option A is wrong because an external scan only sees externally exposed services and cannot assess internal configurations or installed patches — it is a scope descriptor, not a depth descriptor. Option B is wrong because a passive scan only observes network traffic without sending probes, so it cannot enumerate vulnerabilities on hosts that are not actively communicating. Option D is wrong because an unauthenticated scan lacks credentials and therefore cannot access detailed configuration information, resulting in more false positives and missed local vulnerabilities.

33
MCQmedium

A penetration tester is engaged to assess a corporate wireless network. After capturing handshakes and attempting offline cracking, the tester obtains valid PSK credentials for the guest SSID. The tester then connects to the guest network but cannot reach any internal servers. Which of the following BEST describes what the tester has demonstrated?

A.The tester has achieved partial network access but is contained by network segmentation controls, which is a valid finding for the engagement.
B.The tester has failed the engagement because no internal systems were compromised during the assessment.
C.The tester should immediately escalate to a full internal penetration test without notifying the client because the guest network is a bridge to the internal environment.
D.The PSK compromise is irrelevant because guest networks are inherently untrusted and require no security controls.
AnswerA

Compromising the guest PSK and being unable to reach internal resources demonstrates that the guest network is segmented from the internal environment. This is a genuine security finding because it shows the control is working as designed while also confirming credential compromise is possible. The tester should document both the successful PSK compromise and the effective segmentation.

Why this answer

Reaching only the guest segment after cracking its PSK shows the segmentation control is functioning and limits lateral movement. The engagement's value is in documenting both the credential weakness and the effective containment. A tester reports what was achieved within scope rather than treating lack of internal compromise as failure or escalating without authorization.

Exam trap

The trap here is assuming that a penetration test is only successful if internal systems are compromised, when containment itself is a reportable finding.

34
MCQhard

After a penetration test, the tester provides a report that includes vulnerabilities found, exploitation details, and recommended fixes. Which step of the penetration testing process does this represent?

A.Reporting
B.Post-exploitation
C.Planning and scoping
D.Reconnaissance
AnswerA

Reporting is the formal, final phase of a penetration testing engagement where the tester documents discovered vulnerabilities, methodology, and risk ratings. This deliverable translates technical findings into actionable remediation steps for both executive and technical stakeholders, marking the official conclusion of the active assessment.

Why this answer

The reporting phase is the final step in the penetration testing process, where the tester documents all findings, including vulnerabilities discovered, exploitation details, and recommended remediation steps. This report is delivered to the client to provide a clear understanding of the security posture and actionable fixes. Without this step, the test results would have no value for improving security.

Exam trap

The trap here is that candidates may confuse 'post-exploitation' with the final reporting step, because post-exploitation involves documenting actions taken after access, but the formal report is a separate, distinct phase that synthesizes all findings from the entire test.

How to eliminate wrong answers

Option B (Post-exploitation) is wrong because post-exploitation occurs after gaining access and involves activities like maintaining persistence, escalating privileges, or exfiltrating data, not compiling and delivering the final report. Option C (Planning and scoping) is wrong because this initial phase defines the test's boundaries, rules of engagement, and objectives, not the documentation of results. Option D (Reconnaissance) is wrong because reconnaissance is the information-gathering phase (e.g., using tools like Nmap or Shodan) to identify targets, not the reporting of exploitation outcomes.

35
MCQeasy

During a penetration test, the tester successfully exploits a vulnerability in a web server and gains initial access. The next step in the penetration testing process is to:

A.Disconnect from the network
B.Report the findings immediately
C.Conduct post-exploitation and lateral movement
D.Perform reconnaissance
AnswerC

After successfully exploiting a vulnerability, the next logical and critical step in a penetration test is to conduct post-exploitation activities and attempt lateral movement. Post-exploitation involves maintaining access, escalating privileges, and gathering information from the compromised system, while lateral movement aims to pivot to other systems within the network. These actions are essential for determining the true impact of the initial compromise, identifying additional vulnerabilities, and mapping the potential blast radius of an attacker, thereby providing a comprehensive security assessment.

Why this answer

After gaining initial access during a penetration test, the standard methodology (e.g., PTES, OWASP) requires conducting post-exploitation and lateral movement to assess the full impact of the compromise. This involves enumerating the compromised host, escalating privileges, and pivoting to other systems using techniques like pass-the-hash or SSH tunneling. Reporting findings immediately or disconnecting would violate the test scope and fail to demonstrate the real risk of the vulnerability.

Exam trap

The trap here is that candidates confuse the linear 'reconnaissance → exploitation → reporting' model with the iterative nature of penetration testing, where post-exploitation and lateral movement are essential steps after initial access to fully assess risk.

How to eliminate wrong answers

Option A is wrong because disconnecting from the network aborts the test prematurely, preventing the tester from identifying the full attack path and potential data exposure, which is the core objective of a penetration test. Option B is wrong because reporting findings immediately after initial access is not part of the penetration testing process; findings are typically documented and reported after the test concludes, not during active exploitation. Option D is wrong because reconnaissance is performed before exploitation, not after gaining initial access; it involves passive and active information gathering (e.g., DNS enumeration, port scanning) to identify targets and vulnerabilities.

36
MCQmedium

A security analyst is tasked with identifying vulnerabilities in a network without exploiting them. Which type of assessment is most appropriate?

A.Vulnerability assessment
B.Security audit
C.Penetration test
D.Security review
AnswerA

A vulnerability assessment systematically identifies security weaknesses and misconfigurations within systems, applications, or networks. It typically employs automated scanning tools and manual analysis to detect known vulnerabilities, providing a prioritized list of potential risks without attempting to exploit them. This process aims to give an organization a comprehensive overview of its security posture and areas requiring remediation.

Why this answer

A vulnerability assessment is designed to identify and enumerate vulnerabilities in a system or network without exploiting them. It typically uses automated scanners and manual techniques to produce a report of potential weaknesses. This matches the requirement of identifying vulnerabilities without exploitation.

Exam trap

The trap is conflating vulnerability assessment with penetration testing; candidates often pick penetration test because it sounds more thorough, but the key differentiator is that pen tests exploit vulnerabilities, while assessments do not.

How to eliminate wrong answers

Option B is wrong because a security audit is a broader evaluation of compliance with policies, standards, and procedures, not specifically focused on identifying technical vulnerabilities. Option C is wrong because a penetration test actively exploits vulnerabilities to demonstrate impact, which violates the 'without exploiting them' constraint. Option D is wrong because a security review is a general term for examining security controls and may not include technical vulnerability identification.

37
MCQmedium

A vulnerability scanner reports a vulnerability with a CVSS score of 9.8. What does this score indicate?

A.High severity
B.Medium severity
C.Low severity
D.Critical severity
AnswerD

A CVSS score of 9.8 unequivocally falls within the Critical severity range, defined as scores from 9.0 to 10.0. This classification signifies vulnerabilities that are extremely severe, often easily exploitable, and can lead to complete loss of confidentiality, integrity, or availability without requiring user interaction or elevated privileges. Such a high score demands immediate attention and remediation due to the profound potential for widespread damage and business disruption.

Why this answer

A CVSS score of 9.8 falls within the range of 9.0–10.0, which is classified as 'Critical' severity according to the CVSS v3.1 specification. This score typically indicates a vulnerability that can be exploited remotely without authentication and with low attack complexity, often leading to complete compromise of confidentiality, integrity, and availability.

Exam trap

The trap here is that candidates may confuse the CVSS v3.1 severity rating scale with the older v2 scale, where scores of 7.0–10.0 were all labeled 'High', but in v3.1, 9.0–10.0 is explicitly 'Critical'.

How to eliminate wrong answers

Option A is wrong because 'High severity' corresponds to CVSS scores of 7.0–8.9, not 9.8. Option B is wrong because 'Medium severity' corresponds to scores of 4.0–6.9, which is far below 9.8. Option C is wrong because 'Low severity' corresponds to scores of 0.1–3.9, and a score of 9.8 is at the top of the scale, not low.

38
MCQeasy

Which vulnerability scoring system is commonly used to assess the severity of vulnerabilities?

A.CVSS
B.NVD
C.CVE
D.OWASP
AnswerA

CVSS provides a standardised, vendor-neutral framework that scores vulnerabilities from 0.0 to 10.0 across base, temporal and environmental metrics, satisfying the stem's requirement for a commonly used severity assessment system. Its base metric group alone captures exploitability and impact, enabling consistent prioritisation across disparate platforms and tooling.

Why this answer

The Common Vulnerability Scoring System (CVSS) is the industry-standard framework for assigning a numerical severity score (0–10) to a vulnerability based on metrics like attack vector, complexity, privileges required, and impact. It is maintained by the Forum of Incident Response and Security Teams (FIRST) and is widely adopted by organizations for prioritization in vulnerability management. CVSS provides a consistent, quantitative measure that allows security teams to compare and triage vulnerabilities across different systems and vendors.

Exam trap

The CISSP exam often tests the distinction between a vulnerability database (NVD), a naming standard (CVE), and a scoring system (CVSS), so the trap here is confusing the repository or identifier with the actual scoring methodology.

How to eliminate wrong answers

Option B (NVD) is wrong because the National Vulnerability Database (NVD) is a repository of vulnerability data that uses CVSS scores, but it is not itself a scoring system; it is a database that references CVSS. Option C (CVE) is wrong because the Common Vulnerabilities and Exposures (CVE) system is a dictionary of unique identifiers for publicly known vulnerabilities, not a scoring or severity assessment system. Option D (OWASP) is wrong because the Open Web Application Security Project (OWASP) provides guidelines, tools, and frameworks for web application security (e.g., the OWASP Top 10), but it does not define a standardized vulnerability scoring system like CVSS.

39
MCQeasy

An organization's security team wants to validate that its incident response plan works as documented before a real breach occurs. The team needs to exercise communication paths, decision-making, and coordination among technical staff, legal, and public relations without touching production systems. Which of the following is the MOST appropriate exercise type?

A.A vulnerability scan of the production environment to identify weaknesses the plan should address
B.A penetration test conducted by an external firm to simulate a real attacker
C.A full-scale simulation that disables production systems to test real recovery capabilities
D.A tabletop exercise where participants discuss their roles and responses to a simulated scenario
AnswerD

A tabletop exercise gathers stakeholders in a discussion-based setting to walk through a simulated incident, exercising communication, decision-making, and coordination without affecting production. It directly matches the goal of validating the plan and involving legal and public relations personnel in a low-risk environment.

Why this answer

A tabletop exercise is discussion-based and designed to validate plans, roles, and coordination among diverse stakeholders without impacting production. It exercises communication and decision-making with legal and public relations participants, matching the stated goal. Full-scale simulations, vulnerability scans, and penetration tests address different objectives and either disrupt production or fail to exercise the plan.

Exam trap

The trap here is selecting the highest-fidelity exercise such as a full-scale simulation when the objective is low-risk validation of plans and coordination.

40
MCQhard

An organization wants to ensure that its web application is secure by analyzing the source code for vulnerabilities without executing the code. Which type of testing is most appropriate?

A.Interactive Application Security Testing (IAST)
B.Dynamic Application Security Testing (DAST)
C.Runtime Application Self-Protection (RASP)
D.Static Application Security Testing (SAST)
AnswerD

Static Application Security Testing (SAST) directly analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the program. It identifies potential flaws such as buffer overflows, SQL injection vulnerabilities, and insecure coding practices by examining the code structure and data flow paths. This 'shift-left' approach allows developers to find and fix security defects early in the software development lifecycle, before deployment.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, making it the only option that matches the requirement of reviewing code for vulnerabilities in a non-running state. SAST tools perform data-flow and control-flow analysis to detect issues like SQL injection, buffer overflows, and hardcoded secrets directly in the codebase. Because it operates pre-execution, it can be integrated early in the SDLC (shift-left) and pinpoint the exact file and line of a flaw.

Exam trap

CISSP often tests the distinction between static (non-running code) and dynamic (running application) testing, and candidates frequently confuse IAST with SAST because both can involve code analysis, but IAST requires execution.

How to eliminate wrong answers

Option A is wrong because IAST instruments a running application (often via an agent) and analyzes traffic and execution flow during runtime, so it requires code execution. Option B is wrong because DAST tests a running application from the outside by sending malicious requests and observing responses, which is black-box and does not examine source code. Option C is wrong because RASP is a runtime protection mechanism embedded in the application that detects and blocks attacks as they occur, not a source-code analysis technique.

41
Multi-Selecthard

Which THREE of the following are valid types of penetration testing based on the level of knowledge provided to the tester?

Select 3 answers
A.Blue box
B.White box
C.Grey box
D.Black box
E.Red box
AnswersB, C, D

White-box penetration testing, also known as clear-box testing, provides the assessor with complete access to system documentation, source code, network diagrams, and IP addressing schemes. This comprehensive visibility allows for a highly thorough security assessment, simulating an insider threat or a scenario where an attacker has obtained deep administrative access.

Why this answer

The three valid penetration-testing types classified by the tester's level of knowledge are White box (B), Grey box (C), and Black box (D). White box testing gives the tester full knowledge of the target, including source code, architecture, and credentials, making it the highest-knowledge category. Grey box testing provides partial knowledge, such as limited documentation or user-level credentials, simulating an insider with some access.

Black box testing provides no prior knowledge of the target, simulating an external attacker who must perform reconnaissance. Blue box (A) and Red box (E) are not standard knowledge-based penetration-testing classifications; 'blue team' and 'red team' refer to defensive and offensive roles, not levels of tester knowledge.

Exam trap

CISSP often tests the three knowledge-based pen test types (white, grey, black) while seeding color-based distractors like 'blue box' and 'red box' that refer to team roles, not testing methodologies — candidates who conflate team colors with test types select the wrong options.

42
MCQmedium

A security team is reviewing application security and needs to analyze source code without executing the application. Which technique should they use?

A.Dynamic Application Security Testing (DAST)
B.Interactive Application Security Testing (IAST)
C.Static Application Security Testing (SAST)
D.Runtime Application Self-Protection (RASP)
AnswerC

Static Application Security Testing (SAST) directly analyzes an application's source code, bytecode, or binary code without actually executing the program. This method allows security teams to identify potential vulnerabilities, such as buffer overflows, SQL injection flaws, or insecure cryptographic practices, early in the Software Development Life Cycle (SDLC). SAST is ideal for reviewing application security during development, enabling developers to fix issues before the application is even compiled or deployed.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, looking for vulnerabilities such as injection flaws, hardcoded secrets, and insecure patterns. Because it operates on the code itself, it can be run early in the SDLC and integrated into CI/CD pipelines. This matches the requirement to analyze source code without executing the application.

Exam trap

CISSP often tests the distinction between testing techniques that require execution (DAST, IAST, RASP) and those that do not (SAST), so the trap is selecting a runtime technique when the question explicitly says the application is not executed.

How to eliminate wrong answers

Option A is wrong because DAST tests a running application from the outside, sending requests and analyzing responses, which requires execution. Option B is wrong because IAST instruments a running application (often via an agent) and analyzes behavior during execution, so it also requires the app to run. Option D is wrong because RASP runs inside a live application at runtime to detect and block attacks, which by definition requires execution.

43
Multi-Selectmedium

An organization is planning an external audit for SOC 2 Type II compliance. Which TWO of the following are true about this type of audit?

Select 2 answers
A.It reports on controls over a period of time, typically 6–12 months
B.It is a third-party audit that evaluates controls for security, availability, processing integrity, confidentiality, and privacy
C.It is an internal audit performed by the organization's staff
D.It focuses solely on financial reporting controls
E.It is a public document available to anyone
AnswersA, B

A SOC 2 Type II report provides an in-depth assessment of a service organization's controls over a specified period, typically spanning six to twelve months. This extended observation period allows the auditor to test the operating effectiveness of controls, demonstrating their consistent application and reliability over time. This contrasts sharply with a Type I report, which only describes controls at a specific point in time without testing their effectiveness.

Why this answer

Option A is correct because a SOC 2 Type II audit reports on the design and operating effectiveness of controls over a period of time, typically a 6–12 month observation window, rather than a single point in time as in a Type I report. Option B is correct because SOC 2 is an independent third-party examination against the AICPA Trust Services Criteria, which cover security (common criteria) plus availability, processing integrity, confidentiality, and privacy. Option C is incorrect because SOC 2 is performed by an independent CPA firm, not by the organization's own internal staff.

Option D is incorrect because SOC 2 addresses the Trust Services Criteria, not financial reporting controls, which are the domain of SOC 1 (SSAE 18/ISAE 3402). Option E is incorrect because SOC 2 reports are restricted-use documents distributed under NDA to management, customers, and other specified parties, not public documents.

Exam trap

CISSP often tests the SOC 1 vs SOC 2 vs SOC 3 distinction — candidates confuse SOC 2 (Trust Services Criteria, restricted use) with SOC 1 (financial reporting) or SOC 3 (general-use, no detail), and mislabel Type II as a point-in-time or internal audit.

44
Multi-Selectmedium

A security manager is planning a penetration test and needs to ensure proper rules of engagement are established. Which TWO of the following are essential components of the rules of engagement?

Select 2 answers
A.Vulnerability scoring methodology
B.Scope definition including in-scope systems
C.Written authorization from management
D.Previous test results
E.List of tools to be used
AnswersB, C

Defining the scope, including specific in-scope systems, IP ranges, applications, and excluded assets, is absolutely foundational for any penetration test. This critical step establishes the precise boundaries of the engagement, preventing unauthorized testing of systems and ensuring legal and ethical compliance. Without a clear scope, testers risk legal repercussions for exceeding authorization, and the client risks unexpected disruption to critical out-of-scope services.

Why this answer

Scope definition (B) is essential because it explicitly lists in-scope systems, IP ranges, and exclusions, preventing unauthorized access and legal liability. Written authorization from management (C) provides the legal and contractual basis for the test, ensuring the penetration test is conducted with informed consent and documented approval.

Exam trap

The trap here is that candidates confuse 'rules of engagement' with the broader 'penetration testing methodology' and mistakenly include operational details like tool lists or scoring methods, which are not required for defining the legal and authorization boundaries.

45
Multi-Selectmedium

During a penetration testing engagement, which TWO of the following are essential components of the rules of engagement document?

Select 2 answers
A.Vulnerability severity ratings
B.Emergency stop criteria
C.Detailed exploit code
D.Scope definition including target systems
E.Written authorization from management
AnswersB, D

Emergency stop criteria are a fundamental component of the Rules of Engagement (ROE), meticulously outlining specific conditions under which all penetration testing activities must immediately cease. These conditions typically include critical system instability, unauthorized data exfiltration, detection by the client's security operations center leading to incident response, or any activity that risks legal or ethical boundaries. Their inclusion is paramount for effective risk management, safeguarding client systems, and preventing unintended harm during the engagement.

Why this answer

In penetration testing, the rules of engagement (ROE) document defines the operational parameters, including emergency stop criteria (Option B) and scope definition (Option D). Written authorization from management (Option E) is a separate prerequisite document granting legal permission to test; it is not part of the ROE. Vulnerability severity ratings (Option A) are found in the final report, and detailed exploit code (Option C) is a technical artifact not included in the ROE.

Exam trap

In the CISSP exam, candidates often mistakenly include 'written authorization from management' as a component of the rules of engagement (ROE) when it is actually a separate prerequisite document. The ROE contains operational constraints like emergency stop criteria and scope definition, while authorization is a distinct legal permission to test.

46
MCQhard

A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?

A.Patch compliance percentage
B.ROI of security controls
C.Mean time to remediate critical vulnerabilities
D.Number of open vulnerabilities by severity
AnswerC

Mean time to remediate critical vulnerabilities is a direct and highly effective metric for measuring the operational speed and efficiency of an organization's vulnerability response program. It quantifies the average duration from the initial detection of a critical vulnerability to its complete resolution, including patching, configuration changes, or architectural redesigns. This metric precisely reflects how quickly the security team and supporting IT functions can address the most significant risks, directly indicating the effectiveness of their remediation processes.

Why this answer

Mean time to remediate (MTTR) critical vulnerabilities directly measures how quickly the organization closes its highest-risk exposures, which is the clearest indicator of response speed and program effectiveness. It captures both detection-to-triage and triage-to-fix intervals, so a shrinking MTTR demonstrates improving operational capability. CISSP exam objectives emphasize metrics that reflect responsiveness and risk reduction, not just volume or compliance.

Exam trap

CISSP often tests the difference between coverage/compliance metrics (patch percentage) and responsiveness metrics (MTTR) — candidates pick patch compliance because it sounds like a strong indicator, but the question specifically asks about speed of response.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures coverage (how many systems are patched) rather than speed of response — a system can be 99% compliant yet still take months to patch a newly disclosed critical CVE. Option B is wrong because ROI of security controls is a financial efficiency metric, not a responsiveness or effectiveness measure for vulnerability management. Option D is wrong because the number of open vulnerabilities by severity is a snapshot/backlog metric — it shows exposure volume but says nothing about how fast the team remediates, and a large backlog could still coexist with fast remediation if intake is high.

47
MCQhard

During a penetration test, the tester successfully gains access to a server and then attempts to move laterally to other systems. This phase is known as:

A.Scanning and enumeration
B.Exploitation
C.Reconnaissance
D.Post-exploitation and lateral movement
AnswerD

Post-exploitation begins immediately after initial access to a system is achieved, focusing on maintaining persistence, escalating privileges, and gathering further intelligence from the compromised host. Lateral movement is a critical component of this phase, where the tester utilizes the initial foothold to pivot and gain access to other systems and network segments, expanding their control and understanding of the target environment's internal defenses.

Why this answer

After initial access is gained, the phase where the tester moves from the compromised host to other systems within the network is specifically called post-exploitation and lateral movement. This involves using the foothold to pivot, escalate privileges, and access additional resources, which is distinct from the initial exploitation step.

Exam trap

The trap here is that candidates confuse 'exploitation' (the initial breach) with the broader post-exploitation phase, forgetting that lateral movement is a distinct activity that occurs after the initial foothold is established.

How to eliminate wrong answers

Option A is wrong because scanning and enumeration occur before exploitation to identify open ports, services, and potential vulnerabilities, not after gaining access. Option B is wrong because exploitation is the act of leveraging a vulnerability to gain initial access, not the subsequent movement to other systems. Option C is wrong because reconnaissance is the initial information-gathering phase (passive or active) performed before any access is obtained, such as DNS lookups or network mapping.

48
MCQmedium

A company is preparing for an external audit to comply with PCI DSS. Which type of auditor is typically required to perform this assessment?

A.System administrator
B.Internal auditor
C.Certified Public Accountant (CPA)
D.Qualified Security Assessor (QSA)
AnswerD

A Qualified Security Assessor (QSA) is an individual certified by the PCI Security Standards Council (PCI SSC) to conduct formal PCI DSS compliance assessments. QSAs possess specialized expertise in the technical and procedural requirements of the standard, ensuring an independent and objective evaluation of an entity's cardholder data environment. Their external validation is mandatory for organizations required to submit a Report on Compliance (ROC) or validate their Self-Assessment Questionnaire (SAQ) with a QSA attestation, providing the necessary assurance to payment brands.

Why this answer

PCI DSS requires assessments to be conducted by a Qualified Security Assessor (QSA) because QSAs are certified by the PCI Security Standards Council to validate compliance with the standard's technical and procedural controls. Unlike internal or general external auditors, QSAs have specific training in PCI DSS requirements, including network segmentation, encryption protocols (e.g., TLS 1.2+), and logging mechanisms (e.g., audit trails per Requirement 10).

Exam trap

The trap here is that candidates confuse 'external auditor' with any certified accountant or general IT auditor, overlooking that PCI DSS mandates a specifically certified QSA for compliance validation, not just any third-party assessor.

How to eliminate wrong answers

Option A is wrong because a system administrator lacks the independent, certified authority required for PCI DSS compliance validation and would create a conflict of interest by assessing their own systems. Option B is wrong because internal auditors, while independent within the organization, are not recognized by the PCI Security Standards Council to issue a formal Report on Compliance (ROC) for Level 1 merchants or service providers. Option C is wrong because a Certified Public Accountant (CPA) may perform financial audits but does not hold the specialized PCI DSS technical expertise (e.g., firewall rule reviews, vulnerability scanning per ASV standards) required for a QSA assessment.

49
MCQmedium

An organization is preparing for an ISO 27001 certification audit. The audit will be performed by an external body. This type of audit is classified as:

A.Self-assessment
B.External audit
C.Peer review
D.Internal audit
AnswerB

An external audit is a formal, systematic examination performed by an independent, accredited third-party certification body to verify an organization's conformity with the ISO 27001 standard. This impartial assessment ensures objectivity and credibility, providing the necessary assurance for official certification. It is the definitive step required to achieve and maintain ISO 27001 compliance, as only an external body can grant the certification.

Why this answer

An external audit is performed by an independent third-party organization, such as a certification body, to assess compliance against a standard like ISO 27001. In this scenario, the audit is conducted by an external body specifically for certification purposes, which directly matches the definition of an external audit. This type of audit provides an unbiased evaluation of the Information Security Management System (ISMS) and is required for formal certification.

Exam trap

The trap here is confusing an internal audit (conducted by the organization's own staff) with an external audit (conducted by an independent third party), especially when the question emphasizes 'preparing for certification' — candidates may mistakenly think internal audits are sufficient for certification, but only an external audit by an accredited body can grant ISO 27001 certification.

How to eliminate wrong answers

Option A is wrong because a self-assessment is an internal evaluation performed by the organization's own staff, not by an external certification body. Option C is wrong because a peer review typically involves a review by colleagues or other organizations in a non-certification context, not a formal audit by an accredited external body. Option D is wrong because an internal audit is conducted by the organization's own internal audit team or employees, not by an independent external auditor.

50
MCQmedium

A developer uses a tool that analyzes source code for potential security flaws without executing the program. This is an example of:

A.DAST
B.IAST
C.RASP
D.SAST
AnswerD

SAST (Static Application Security Testing) directly examines an application's source code, bytecode, or binary code without executing it, making it a 'white-box' testing method. It identifies potential vulnerabilities such as buffer overflows, SQL injection flaws, or insecure coding practices by analyzing the code's structure, data flow, and control flow statically. This approach is ideal for developers to find and fix security flaws early in the Software Development Life Cycle (SDLC) before deployment.

Why this answer

SAST (Static Application Security Testing) analyzes source code, bytecode, or binary code for security vulnerabilities without executing the program. This matches the description of a tool that inspects code statically, making D the correct answer.

Exam trap

The trap here is confusing SAST with DAST because both are application security testing types, but the key differentiator is execution: SAST is static (no execution) while DAST is dynamic (requires execution).

How to eliminate wrong answers

Option A is wrong because DAST (Dynamic Application Security Testing) tests a running application by sending inputs and observing responses, not by analyzing source code without execution. Option B is wrong because IAST (Interactive Application Security Testing) combines static and dynamic analysis, requiring the application to be executed and instrumented, not purely static analysis. Option C is wrong because RASP (Runtime Application Self-Protection) is a runtime security control embedded in the application environment that monitors and blocks attacks during execution, not a source code analysis tool.

51
Multi-Selectmedium

An organization is selecting security metrics to report to the board. Which THREE metrics would best demonstrate the effectiveness of the vulnerability management program?

Select 3 answers
A.Open vulnerability count by severity
B.Number of employees in IT security
C.Budget for security tools
D.Mean time to remediate critical vulnerabilities
E.Patch compliance percentage
AnswersA, D, E

Tracking open vulnerabilities segmented by severity (critical, high, medium, low) gives the board a direct, current-state view of unremediated risk exposure. Because it's broken out by severity rather than a single aggregate number, it lets leadership see whether the highest-risk items are being prioritized correctly, and trends over time reveal whether the program is keeping pace with new findings or falling behind.

Why this answer

These three metrics cover remediation speed, current risk posture, and compliance with patching policies, which are key indicators.

52
MCQmedium

An organization wants to test its web application for vulnerabilities by running the application and probing it with malicious inputs. Which tool is BEST suited for this purpose?

A.OWASP ZAP
B.Checkmarx
C.SonarQube
D.Veracode
AnswerA

OWASP ZAP is a leading open-source Dynamic Application Security Testing (DAST) tool specifically designed to find vulnerabilities in running web applications. It actively proxies HTTP/S traffic, allowing it to scan for common web vulnerabilities like SQL injection, Cross-Site Scripting (XSS), and broken authentication by interacting with the application as a real user would. This makes it ideal for identifying security flaws that manifest at runtime, after the application has been deployed.

Why this answer

OWASP ZAP (Zed Attack Proxy) is a dynamic application security testing (DAST) tool that runs the application and actively probes it with malicious inputs, making it the correct choice for runtime vulnerability testing. It intercepts and modifies HTTP/S traffic, performs active scanning for injection, XSS, and misconfigurations, and is specifically designed for testing running web applications.

Exam trap

CISSP often tests the SAST vs. DAST distinction — candidates pick Checkmarx or Veracode because they recognize them as security tools, forgetting those analyze code statically rather than probing a running application.

How to eliminate wrong answers

Option B is wrong because Checkmarx is a static application security testing (SAST) tool that analyzes source code without executing the application, so it cannot probe a running app with malicious inputs. Option C is wrong because SonarQube is a code quality and static analysis platform that inspects source code for bugs and code smells, not a runtime DAST scanner. Option D is wrong because Veracode is primarily a SAST and software composition analysis (SCA) platform (with some DAST capability) that analyzes binaries and source rather than running the application and probing it interactively.

53
MCQhard

A company's security team uses a tool that instruments the application at runtime to monitor and block attacks. This is an example of:

A.IAST
B.RASP
C.SAST
D.DAST
AnswerB

RASP (Runtime Application Self-Protection) directly integrates with the application's runtime environment, actively monitoring its execution, data inputs, and outputs in real-time. By instrumenting the application, RASP can detect and immediately block malicious requests or anomalous behavior that indicates an attempted exploit, such as SQL injection or cross-site scripting. Its core purpose is to provide continuous, self-contained protection against attacks in live production systems.

Why this answer

RASP (Runtime Application Self-Protection) instruments the application at runtime, embedding security checks inside the application to detect and block attacks in real time. It operates within the application's execution context, allowing it to monitor data flow, method calls, and user input.

Exam trap

CISSP often tests the distinction between testing tools (SAST, DAST, IAST) and runtime protection (RASP) — the trap is selecting IAST because it also instruments the application, but IAST is used during testing, not for blocking attacks in production.

How to eliminate wrong answers

Option A is wrong because IAST (Interactive Application Security Testing) is a testing methodology that combines static and dynamic analysis during QA/testing; it identifies vulnerabilities but does not block attacks in production. Option C is wrong because SAST (Static Application Security Testing) analyzes source code without executing it, typically during development, and cannot block runtime attacks. Option D is wrong because DAST (Dynamic Application Security Testing) tests a running application from the outside (black-box) to find vulnerabilities, but it does not instrument the application or block attacks in real time.

Ready to test yourself?

Try a timed practice session using only Security Assessment and Testing questions.