hardMultiple SelectObjective-mapped
CISSP Practice Question: Which THREE of the following are common methods…
Which THREE of the following are common methods used in security assessment and testing? (Select exactly 3.)
⚠ Common exam trap
Test-takers frequently confuse risk analysis (a management activity) with security testing, or mistake forensic analysis (a reactive process) for a proactive assessment method, leading them to select options outside the three correct ones (penetration testing, security auditing, vulnerability scanning).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Penetration testing
Penetration testing is a common method in security assessment and testing that simulates real-world attacks to identify exploitable vulnerabilities. Unlike vulnerability scanning, which only identifies potential weaknesses, penetration testing actively exploits them to validate security controls and measure the impact of a breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk analysis
Why it's wrong here
Risk analysis is a foundational component of risk management, not a direct technical security assessment or testing method. Its primary purpose is to identify, evaluate, and prioritize potential threats and vulnerabilities, assessing their likelihood and impact on organizational assets. While crucial for informing security decisions and resource allocation, it does not involve actively probing systems or controls for weaknesses.
- ✓
Penetration testing
Why this is correct
Penetration testing is a highly effective and common method for proactively assessing an organization's security posture by simulating real-world attacks. Ethical hackers attempt to exploit identified vulnerabilities in systems, applications, and networks to determine the extent to which an attacker could compromise assets. This hands-on approach provides valuable insights into the effectiveness of existing security controls and the potential impact of a successful breach.
- ✓
Security auditing
Why this is correct
Security auditing is a systematic process designed to evaluate the effectiveness and compliance of an organization's security policies, procedures, and controls against established standards, regulations, or internal guidelines. It involves reviewing documentation, interviewing personnel, and examining system configurations to ensure adherence to security requirements. Auditing provides assurance that controls are properly implemented and operating as intended, focusing on governance and compliance rather than active exploitation.
- ✗
Forensic analysis
Why it's wrong here
Forensic analysis is a specialized discipline primarily employed *after* a security incident has occurred, making it a reactive rather than a proactive assessment method. Its objective is to meticulously collect, preserve, and analyze digital evidence from compromised systems to determine the root cause, scope, and impact of a breach. This process is critical for incident response, legal proceedings, and understanding how to prevent future occurrences, but it doesn't proactively identify vulnerabilities.
- ✓
Vulnerability scanning
Why this is correct
Vulnerability scanning is a widely used automated method for identifying known security weaknesses and misconfigurations within an organization's IT infrastructure. These scans leverage databases of common vulnerabilities and exposures (CVEs) to detect potential flaws in operating systems, applications, and network devices. While effective for broad coverage and identifying low-hanging fruit, scanning typically does not exploit vulnerabilities or assess the full impact of a successful attack.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security assessment
A security assessment is a systematic evaluation of an organization’s systems, networks, and applications to identify vulnerabilities, threats, and risks, and to recommend improvements.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.