ISC2 Certified in Cybersecurity (CC)Security OperationsMedium

A security team is conducting a comprehensive evaluation of an organization's cloud infrastructure to identify misconfigurations, weak access controls, and potential vulnerabilities from an attacker's perspective. The goal is to simulate real-world attacks to uncover exploitable flaws. Which security assessment technique are they employing?

  1. AVulnerability scanning
  2. BPenetration testing
  3. CSecurity audit
  4. DSecurity monitoring
Show answer & explanation

Correct answer: B. Penetration testing

Penetration testing simulates real-world attacks to actively exploit identified vulnerabilities and misconfigurations from an attacker's perspective, providing a deeper understanding of actual risk than scanning alone.

Why the other options are wrong

  • A. Vulnerability scanning identifies known weaknesses but does not attempt to exploit them or simulate an attacker's perspective.
  • C. A security audit checks compliance against policies and standards, not active exploitation of vulnerabilities from an attacker's view.
  • D. Security monitoring is about detecting ongoing threats and incidents, not proactive simulation of attacks.

Penetration Testing

A simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.

  • Actively exploits weaknesses.
  • Simulates real-world attacker behavior.
  • Provides a true measure of security posture.

Memory trick: Pen test: attack to defend.

More Security Operations questions