Courseiva
hardMultiple SelectObjective-mapped

CISSP Practice Question: Which THREE of the following are common methods…

Which THREE of the following are common methods used in security assessment and testing? (Select exactly 3.)

⚠ Common exam trap

Test-takers frequently confuse risk analysis (a management activity) with security testing, or mistake forensic analysis (a reactive process) for a proactive assessment method, leading them to select options outside the three correct ones (penetration testing, security auditing, vulnerability scanning).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Penetration testing

Penetration testing is a common method in security assessment and testing that simulates real-world attacks to identify exploitable vulnerabilities. Unlike vulnerability scanning, which only identifies potential weaknesses, penetration testing actively exploits them to validate security controls and measure the impact of a breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk analysis

    Why it's wrong here

    Risk analysis is a foundational component of risk management, not a direct technical security assessment or testing method. Its primary purpose is to identify, evaluate, and prioritize potential threats and vulnerabilities, assessing their likelihood and impact on organizational assets. While crucial for informing security decisions and resource allocation, it does not involve actively probing systems or controls for weaknesses.

  • Penetration testing

    Why this is correct

    Penetration testing is a highly effective and common method for proactively assessing an organization's security posture by simulating real-world attacks. Ethical hackers attempt to exploit identified vulnerabilities in systems, applications, and networks to determine the extent to which an attacker could compromise assets. This hands-on approach provides valuable insights into the effectiveness of existing security controls and the potential impact of a successful breach.

  • Security auditing

    Why this is correct

    Security auditing is a systematic process designed to evaluate the effectiveness and compliance of an organization's security policies, procedures, and controls against established standards, regulations, or internal guidelines. It involves reviewing documentation, interviewing personnel, and examining system configurations to ensure adherence to security requirements. Auditing provides assurance that controls are properly implemented and operating as intended, focusing on governance and compliance rather than active exploitation.

  • Forensic analysis

    Why it's wrong here

    Forensic analysis is a specialized discipline primarily employed *after* a security incident has occurred, making it a reactive rather than a proactive assessment method. Its objective is to meticulously collect, preserve, and analyze digital evidence from compromised systems to determine the root cause, scope, and impact of a breach. This process is critical for incident response, legal proceedings, and understanding how to prevent future occurrences, but it doesn't proactively identify vulnerabilities.

  • Vulnerability scanning

    Why this is correct

    Vulnerability scanning is a widely used automated method for identifying known security weaknesses and misconfigurations within an organization's IT infrastructure. These scans leverage databases of common vulnerabilities and exposures (CVEs) to detect potential flaws in operating systems, applications, and network devices. While effective for broad coverage and identifying low-hanging fruit, scanning typically does not exploit vulnerabilities or assess the full impact of a successful attack.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.