SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
An organization is preparing for an upcoming regulatory compliance audit. The auditor requests evidence of regular security control effectiveness testing. The security manager needs to provide documentation demonstrating that the implemented controls are working as intended against known attack patterns and vulnerabilities. Which type of assessment would BEST fulfill this request?
- APenetration testing
- BVulnerability scanning
- CSecurity audit
- DRisk assessment
Show answer & explanationAnswer & explanation
Correct answer: A. Penetration testing
Penetration testing actively attempts to exploit vulnerabilities to determine if security controls are effective against real-world attack patterns, thus providing concrete evidence of control effectiveness, which is precisely what the auditor is requesting for compliance.
Why the other options are wrong
- B. Vulnerability scanning identifies potential weaknesses but doesn't prove whether controls prevent successful exploitation.
- C. A security audit is a broader review of security policies and controls, but penetration testing is a specific method to test control effectiveness.
- D. A risk assessment identifies and analyzes risks but doesn't actively test the effectiveness of existing controls.
Penetration Testing
Penetration testing (pen testing) is a simulated cyberattack against your computer system to check for exploitable vulnerabilities. It's used to evaluate the security of a system or network by safely trying to exploit weaknesses.
- Actively attempts to exploit vulnerabilities.
- Tests the effectiveness of security controls.
- Provides a realistic view of an organization's security posture.
- Goes beyond identifying vulnerabilities to prove exploitability.
Memory trick: To truly know if your shield works, you must try to pierce it.