ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingEasy

A security team is implementing a continuous monitoring program. They want to ensure that security controls remain effective over time and that any deviations from established baselines are quickly identified. Which of the following security assessment strategies is best suited for this ongoing objective?

  1. AContinuous security monitoring
  2. BRegular compliance audits
  3. COne-time penetration testing
  4. DAnnual vulnerability assessments
Show answer & explanation

Correct answer: A. Continuous security monitoring

Continuous security monitoring is designed for ongoing assessment of security controls and immediate identification of deviations, directly aligning with the objective of ensuring effectiveness over time and quick detection of changes.

Why the other options are wrong

  • B. Regular compliance audits check adherence to rules, but don't inherently provide continuous real-time control effectiveness monitoring.
  • C. One-time penetration testing provides a snapshot, not continuous assurance.
  • D. Annual vulnerability assessments are periodic, not continuous, and may miss real-time deviations.

Continuous Security Monitoring

An ongoing process of collecting, analyzing, and reporting on security-related data to detect threats, vulnerabilities, and deviations from security policies in real-time or near real-time.

  • Provides real-time visibility into security posture
  • Detects deviations from baselines promptly
  • Supports proactive risk management

Memory trick: Assessments: Snapshots, Deep Dives, or Constant Watches.

More Security Assessment and Testing questions