ISC2 CISSP (Certified Information Systems Security Professional)Security Assessment and TestingEasy

A security engineer is tasked with evaluating the effectiveness of security controls in a new cloud-native application. The engineer decides to simulate a real-world attack by attempting to exploit known vulnerabilities and misconfigurations in a production-like environment. Which type of security assessment is the engineer performing?

  1. ASecurity Audit
  2. BPenetration Test
  3. CCompliance Review
  4. DVulnerability Scan
Show answer & explanation

Correct answer: B. Penetration Test

A penetration test involves actively exploiting vulnerabilities to determine the extent to which an attacker can gain unauthorized access or cause damage. Simulating a real-world attack in a production-like environment aligns perfectly with the definition of a penetration test.

Why the other options are wrong

  • A. A security audit is a systematic evaluation of security controls against a set of criteria, often involving documentation review and interviews, not active exploitation.
  • C. A compliance review checks adherence to regulations or standards, typically through documentation and interviews, not active attack simulation.
  • D. A vulnerability scan identifies weaknesses but does not attempt to exploit them.

Penetration Test

A simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.

  • Involves active exploitation of vulnerabilities.
  • Aims to determine the real-world impact of a breach.
  • Can be black-box, white-box, or gray-box.

Memory trick: ASSESSMENTS range from passive SCANS to active PEN TESTS, ensuring COMPLIANCE and AUDIT integrity.

More Security Assessment and Testing questions