Study. uk . com
  1. Home
  2. All questions
  3. Question 53

CISSP study material · question 53 of 500

A compliance analyst at a regional insurer must confirm that firewall change records and the current rulesets agree with documented policy, with no interruption to claims processing. The engagement letter allows the analyst to review artefacts only, with no interaction with live devices. Which assessment method fits this work?

  1. Examination, which inspects objects such as documents, logs and rulesets to gain evidence and understanding
  2. Interviewing, which holds discussions with staff to clarify issues and learn where supporting evidence sits
  3. Penetration testing, which exploits a confirmed weakness to demonstrate the impact an adversary could achieve
  4. Testing, which exercises objects under specified conditions and compares observed behaviour against expected behaviour
Show the answer

Answer: A. Examination, which inspects objects such as documents, logs and rulesets to gain evidence and understanding

Examination is the passive review of documents, logs and rulesets. Only testing involves hands-on interaction with the object, which this engagement forbids.

Source: NIST SP 800-115 (NIST) — SP 800-115 > Section 2, Security Testing and Examination Overview

Challenge yourself on this topic → Study as cards