CISSP - Security Assessment and Testing (12% of the exam) - Section 6.2

Conduct security control testing including vulnerability assessment, penetration testing, log reviews, code review, and breach attack simulations.

Conduct security control testing using vulnerability assessment, penetration testing, log reviews, code review, interface testing, and breach attack simulations to validate control effectiveness. Interpret test findings to distinguish confirmed vulnerabilities from false positives and prioritise remediation by risk.

vulnerability assessmentpenetration testingcode reviewinterface testingbreach attack simulation

Practice question for this objective

Free sampleSecurity Assessment and Testinghard

A CISO is briefing the board on the role of a breach and attack simulation platform versus a traditional annual penetration test. Which statement BEST describes what a breach and attack simulation programme is designed to provide that an annual penetration test does not?

  • AA guarantee that all production exploitable weaknesses have been remediated before the next reporting cycle, replacing the need for a separate penetration test.
  • BAn adversary emulation exercise indistinguishable from a red team engagement, performed by certified human testers operating outside business hours.
  • CContinuous, automated validation of preventive and detective controls against catalogued adversary techniques, so that control drift is detected between scheduled penetration tests. Correct
  • DA compliance attestation accepted by regulators as equivalent to an independent third-party penetration test for financial services obligations.
Position breach and attack simulation as continuous automated control validation that complements, rather than replaces, periodic penetration testing. Breach and attack simulation platforms safely replay catalogued adversary techniques against production-like environments on a recurring basis, producing trended evidence about whether preventive and detective controls still fire. This addresses control drift between point-in-time penetration tests but does not provide the bespoke human creativity of a red team or the independence demanded by many regulators.

Why A is wrong: This option is tempting because executives often hope for a single tool to subsume penetration testing, but the absolute word all and the framing as a guarantee are red flags. No automation eliminates the residual value of manual testing.

Why B is wrong: This conflates breach and attack simulation with red teaming. The two activities share vocabulary but differ in tempo and human craft. Simulations are automated and repeatable, not bespoke human adversary emulation.

Why C is correct: This captures the design intent of breach and attack simulation: scheduled or near-continuous safe replays of known techniques that measure whether existing controls still prevent, detect, or alert, which complements the deeper but infrequent penetration test.

Why D is wrong: Regulatory frameworks for financial services typically still require independent penetration testing. Simulation evidence supports continuous assurance but does not displace the independent assessment most regulators demand.

See more CISSP practice questions, answers explained.

Exam traps in Security Assessment and Testing

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISSP bank for this domain.

  • A vulnerability assessment is performed without management approval, whereas a penetration test always requires a signed rules-of-engagement document before any activity commences.

    Why it is wrong: Tempting because rules of engagement are most often emphasised for penetration testing, but both activities require written authorisation. Scope and authorisation discipline applies equally; the option mischaracterises assessment governance.

  • Penetration testing inventories every host, port, and patch level across the estate more accurately than authenticated scanning can.

    Why it is wrong: Comprehensive estate inventory and patch-state coverage are strengths of authenticated vulnerability scanning, not penetration testing. Framing the request this way misrepresents the discipline and would not survive scrutiny from a committee that already funds scanning.

  • To confirm that the user interface uses an approved design system and meets accessibility commitments under the organisation's inclusion policy.

    Why it is wrong: Accessibility and design conformance are valuable engineering concerns, but they are not the security purpose of interface testing. Candidates pick this when they read interface as user interface only.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.