Courseiva
mediumMultiple Select

CISSP Practice Question: Which TWO of the following are examples of types…

Which TWO of the following are examples of types of security assessments?

⚠ Common exam trap

Candidates often confuse security assessments (active evaluation of security posture, such as vulnerability scans and penetration tests) with security controls or operational tasks (such as installing firewalls, enforcing policies, or updating antivirus definitions), which are management or maintenance activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability scan

A vulnerability scan (A) is a recognized type of security assessment because it systematically probes hosts, services, and applications for known weaknesses using signature/CVE-based checks, producing a report of findings. A penetration test (E) is also a security assessment type, as it goes beyond scanning by actively exploiting vulnerabilities under a defined scope and rules of engagement to demonstrate real-world impact. The other options are operational or administrative controls rather than assessment types: a firewall rule review (B) is a configuration audit of one control, password policy enforcement (C) is a preventive administrative control, and antivirus update (D) is routine maintenance of a protective tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vulnerability scan

    Why this is correct

    A vulnerability scan is an automated process that identifies known weaknesses or misconfigurations in systems, networks, or applications. It typically uses specialized software to detect potential security flaws without actively exploiting them, providing a report of identified vulnerabilities that could be exploited by attackers. This proactive assessment helps organizations understand their exposure to risks and prioritize remediation efforts.

  • ✗

    Firewall rule review

    Why it's wrong here

    Firewall rule review involves systematically examining existing firewall configurations and rulesets to ensure they align with security policies, compliance requirements, and operational needs. While crucial for maintaining a strong security posture, it is primarily an audit and compliance activity, verifying the correct implementation and effectiveness of controls, rather than a direct assessment of system vulnerabilities or a broad type of security assessment.

  • ✗

    Password policy enforcement

    Why it's wrong here

    Password policy enforcement refers to the technical mechanisms and administrative procedures that ensure users adhere to defined password complexity, length, history, and expiration requirements. This is a preventative operational control designed to reduce the risk of unauthorized access through weak or compromised credentials. It is a specific control mechanism, not a method of assessing security posture or a broad category of security.

  • ✗

    Antivirus update

    Why it's wrong here

    An antivirus update involves downloading and applying the latest virus definitions and software patches to an antivirus program. This essential maintenance activity ensures the antivirus software remains effective against new and emerging malware threats by keeping its threat intelligence current. While vital for the ongoing operation of a specific security control, it is a specific operational task, not a fundamental "type of security" or a broad assessment methodology.

  • ✓

    Penetration test

    Why this is correct

    A penetration test, or pen test, is a simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities. Performed by authorized security professionals, it goes beyond simply identifying vulnerabilities by actively attempting to exploit them to determine the true risk and potential impact of a successful breach. This hands-on, adversarial approach provides a realistic view of an organization's security posture.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.