6.0 Security Assessment and Testing CISSP Practice Quiz

96 exam-style questions covering 12% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A regional bank's internal audit team is planning the annual security assessment program. Executives need a risk-based explanation for assessment test and audit strategies. Which response best aligns with security assessment practice?
  • A. Define assessment scope, objectives, criteria, independence, timing, and evidence requirements before testing begins
  • B. Treat an internal readiness review as if it were an independent external audit
  • C. Skip rules of engagement on a pen test because the team is internal
  • D. Begin assessment testing immediately without defining scope or success criteria

A valid assessment strategy starts with clear boundaries and criteria so results are meaningful and repeatable. This is the correct answer.

A defense contractor is preparing for a CMMC Level 2 readiness assessment. An audit readiness meeting must address assessment test and audit strategies. What should the security professional recommend?
  • A. Define rules of engagement before active testing affects production systems or third-party environments
  • B. Skip RoE documentation because the test is performed internally
  • C. Start a pen test without defined scope or success criteria
  • D. Test every system at the same depth, ignoring risk differences

Rules of engagement prevent testing from causing unauthorized disruption or legal exposure. This is the correct answer.

At a federal civilian agency, the IG office is preparing for a FISMA assessment cycle. The security team must make an assurance decision involving assessment test and audit strategies. What is the best recommendation?
  • A. Let control owners select all evidence with no assessor review
  • B. Align test and audit strategy with business risk, legal obligations, control frameworks, and stakeholder assurance needs
  • C. Equate a readiness check with an independent third-party audit
  • D. Forgo formal RoE because the testing team works for the same employer

Assessment work should focus on controls and systems that matter to the organization's obligations and risk posture. This is the correct answer.

A regional utility is planning a NERC CIP-014 physical and cyber assessment. A proposed testing plan creates risk around assessment test and audit strategies. Which change best addresses the concern?
  • A. Use an internal readiness review as the only audit basis
  • B. Use sampling methods that are documented and appropriate to the population and control being tested
  • C. Run active testing without rules of engagement on the basis of internal trust
  • D. Begin assessment activities without first agreeing scope and acceptance criteria

Sampling must support defensible conclusions about control performance. This is the correct answer.

A federal contractor is preparing an authorization-to-operate package for an updated system. The CISO asks for CISSP-level guidance on assessment test and audit strategies. Which approach is most appropriate?
  • A. Forgo rules of engagement because the team is in-house
  • B. Integrate security assessment activities into system lifecycle gates and change management
  • C. Start a security assessment with no defined success criteria
  • D. Apply uniform testing depth across systems with very different risks

Controls should be assessed before major changes introduce unacceptable risk. This is the correct answer.

A children's hospital is engaging an external assessor for an HIPAA security risk analysis. An assessment review identifies a weakness in assessment test and audit strategies. Which action should be prioritized?
  • A. Apply the same test depth to every system regardless of risk
  • B. Allow auditees to choose evidence without independent assessor review
  • C. Use a risk-based assessment plan that gives higher-risk systems more frequent and deeper testing
  • D. Treat readiness reviews as substitutes for independent external assessments

Risk-based planning helps assurance resources focus where failure would have the greatest impact. This is the correct answer.

A consumer fintech is preparing for a PCI DSS attestation cycle. Executives need a risk-based explanation for assessment test and audit strategies. Which response best aligns with security assessment practice?
  • A. Allow control owners to choose all evidence with no assessor review
  • B. Treat a self-administered readiness check as an external audit
  • C. Validate that test plans include success criteria, expected evidence, responsible parties, and escalation paths
  • D. Skip RoE for a pen test because the testers are employees

A test plan should make it clear how results will be judged and what happens if testing fails. This is the correct answer.

A SaaS provider is preparing for a SOC 2 Type II audit ahead of an enterprise customer review. The CISO asks for CISSP-level guidance on assessment test and audit strategies. Which approach is most appropriate?
  • A. Kick off testing without first defining scope, objectives, or success criteria
  • B. Use uniform test depth across systems regardless of risk classification
  • C. Let control owners cherry-pick evidence with no assessor oversight
  • D. Select internal assessment, external audit, automated testing, manual review, or technical testing based on the assurance objective

Different assessment methods provide different evidence and levels of independence. This is the correct answer.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/isc2-cissp/security-assessment-and-testing/

<a href="https://quizbuffet.com/isc2-cissp/security-assessment-and-testing/">CISSP (ISC2) Security Assessment and Testing practice quiz on QuizBuffet</a>

Other CISSP Domains

← Back to CISSP practice test overview

Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.