CISSP - Security Assessment and Testing - Section 6.2

Conduct security control testing including vulnerability assessment, penetration testing, log reviews, code review, and breach attack simulations.

Conduct security control testing using vulnerability assessment, penetration testing, log reviews, code review, interface testing, and breach attack simulations to validate control effectiveness. Interpret test findings to distinguish confirmed vulnerabilities from false positives and prioritise remediation by risk.

vulnerability assessmentpenetration testingcode reviewinterface testingbreach attack simulation

Practice question for this objective

Free sampleSecurity Assessment and Testinghard

A CISO is briefing the board on the role of a breach and attack simulation platform versus a traditional annual penetration test. Which statement BEST describes what a breach and attack simulation programme is designed to provide that an annual penetration test does not?

  • AA guarantee that all production exploitable weaknesses have been remediated before the next reporting cycle, replacing the need for a separate penetration test.
  • BAn adversary emulation exercise indistinguishable from a red team engagement, performed by certified human testers operating outside business hours.
  • CContinuous, automated validation of preventive and detective controls against catalogued adversary techniques, so that control drift is detected between scheduled penetration tests. Correct
  • DA compliance attestation accepted by regulators as equivalent to an independent third-party penetration test for financial services obligations.
Position breach and attack simulation as continuous automated control validation that complements, rather than replaces, periodic penetration testing. Breach and attack simulation platforms safely replay catalogued adversary techniques against production-like environments on a recurring basis, producing trended evidence about whether preventive and detective controls still fire. This addresses control drift between point-in-time penetration tests but does not provide the bespoke human creativity of a red team or the independence demanded by many regulators.

Why A is wrong: This option is tempting because executives often hope for a single tool to subsume penetration testing, but the absolute word all and the framing as a guarantee are red flags. No automation eliminates the residual value of manual testing.

Why B is wrong: This conflates breach and attack simulation with red teaming. The two activities share vocabulary but differ in tempo and human craft. Simulations are automated and repeatable, not bespoke human adversary emulation.

Why C is correct: This captures the design intent of breach and attack simulation: scheduled or near-continuous safe replays of known techniques that measure whether existing controls still prevent, detect, or alert, which complements the deeper but infrequent penetration test.

Why D is wrong: Regulatory frameworks for financial services typically still require independent penetration testing. Simulation evidence supports continuous assurance but does not displace the independent assessment most regulators demand.

See more CISSP practice questions, answers explained.

More in this domain

Back to all Security Assessment and Testing objectives, or the CISSP cert hub.

Examworthy is not affiliated with or endorsed by (ISC)2. Original, blueprint-aligned practice material only.