mediumMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are key objectives of…
Which TWO of the following are key objectives of a security assessment? (Select exactly 2.)
⚠ Common exam trap
Test-takers frequently confuse the objectives of a security assessment (identify vulnerabilities and assess controls) with the objectives of a penetration test (exploit vulnerabilities) or risk management (prioritize threats), leading them to select options C or D incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify vulnerabilities in systems and applications.
A is correct because identifying vulnerabilities is a primary objective of a security assessment, such as a vulnerability scan or penetration test, which systematically discovers weaknesses in systems and applications (e.g., missing patches, misconfigurations, or insecure code). B is correct because assessing the effectiveness of existing security controls (e.g., firewalls, IDS/IPS, access controls) is a core goal, often achieved through control testing or validation to determine if controls are properly implemented and functioning as intended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify vulnerabilities in systems and applications.
Why this is correct
A primary objective of a security assessment is the systematic discovery of weaknesses or flaws, known as vulnerabilities, within an organization's information systems, applications, and network infrastructure. This proactive identification process helps organizations understand potential attack vectors and exposure points before they can be exploited by malicious actors, forming the essential foundation for subsequent risk mitigation strategies.
- ✓
Assess the effectiveness of existing security controls.
Why this is correct
Security assessments are fundamentally designed to evaluate the operational effectiveness and adequacy of an organization's existing security controls, such as access management, encryption protocols, and network segmentation. This involves determining whether these safeguards are functioning as intended, providing the expected level of protection against identified threats, and meeting relevant compliance standards, thereby ensuring their practical utility beyond mere presence.
- ✗
Exploit vulnerabilities to gain unauthorized access.
Why it's wrong here
Exploiting vulnerabilities to gain unauthorized access is a specific technique employed during penetration testing, which is a specialized type of security assessment, rather than a general objective of all security assessments. The broader purpose of a security assessment is typically to identify vulnerabilities and assess controls, whereas exploitation focuses on demonstrating the real-world impact and feasibility of an attack, which is a distinct and more aggressive phase.
- ✗
Prioritize threats based on business impact.
Why it's wrong here
Prioritizing threats based on their potential business impact is a crucial activity within the broader risk management framework, not a direct objective of the security assessment phase itself. While security assessments provide the necessary data by identifying vulnerabilities and control weaknesses, the subsequent process of analyzing and ranking threats according to their criticality to business operations falls under risk analysis and decision-making, which is a separate, analytical step.
- ✗
Implement new security controls to address findings.
Why it's wrong here
Implementing new security controls or modifying existing ones is a remediation and mitigation activity that occurs *after* a security assessment has been completed and its findings have been thoroughly analyzed. The core objective of the assessment phase is solely to identify security weaknesses, evaluate current defenses, and report on their status, not to undertake the operational deployment or configuration of solutions to address the discovered issues.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security assessment
A security assessment is a systematic evaluation of an organization’s systems, networks, and applications to identify vulnerabilities, threats, and risks, and to recommend improvements.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.