A CISO is briefing the board on the role of a breach and attack simulation platform versus a traditional annual penetration test. Which statement BEST describes what a breach and attack simulation programme is designed to provide that an annual penetration test does not?
- AA guarantee that all production exploitable weaknesses have been remediated before the next reporting cycle, replacing the need for a separate penetration test.
- BAn adversary emulation exercise indistinguishable from a red team engagement, performed by certified human testers operating outside business hours.
- CContinuous, automated validation of preventive and detective controls against catalogued adversary techniques, so that control drift is detected between scheduled penetration tests. Correct
- DA compliance attestation accepted by regulators as equivalent to an independent third-party penetration test for financial services obligations.
Why A is wrong: This option is tempting because executives often hope for a single tool to subsume penetration testing, but the absolute word all and the framing as a guarantee are red flags. No automation eliminates the residual value of manual testing.
Why B is wrong: This conflates breach and attack simulation with red teaming. The two activities share vocabulary but differ in tempo and human craft. Simulations are automated and repeatable, not bespoke human adversary emulation.
Why C is correct: This captures the design intent of breach and attack simulation: scheduled or near-continuous safe replays of known techniques that measure whether existing controls still prevent, detect, or alert, which complements the deeper but infrequent penetration test.
Why D is wrong: Regulatory frameworks for financial services typically still require independent penetration testing. Simulation evidence supports continuous assurance but does not displace the independent assessment most regulators demand.