ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingEasy
A security engineer is tasked with evaluating the effectiveness of security controls in a new cloud-native application. The engineer decides to simulate a real-world attack by attempting to exploit known vulnerabilities and misconfigurations in a production-like environment. Which type of security assessment is the engineer performing?
- ASecurity Audit
- BPenetration Test
- CCompliance Review
- DVulnerability Scan
Show answer & explanationAnswer & explanation
Correct answer: B. Penetration Test
A penetration test involves actively exploiting vulnerabilities to determine the extent to which an attacker can gain unauthorized access or cause damage. Simulating a real-world attack in a production-like environment aligns perfectly with the definition of a penetration test.
Why the other options are wrong
- A. A security audit is a systematic evaluation of security controls against a set of criteria, often involving documentation review and interviews, not active exploitation.
- C. A compliance review checks adherence to regulations or standards, typically through documentation and interviews, not active attack simulation.
- D. A vulnerability scan identifies weaknesses but does not attempt to exploit them.
Penetration Test
A simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.
- Involves active exploitation of vulnerabilities.
- Aims to determine the real-world impact of a breach.
- Can be black-box, white-box, or gray-box.
Memory trick: ASSESSMENTS range from passive SCANS to active PEN TESTS, ensuring COMPLIANCE and AUDIT integrity.