- Home
- All questions
- Security assessment
CISSP study material: Security assessment
66 questions of the 500 in the CISSP — Certified Information Systems Security Professional quiz. Each opens with its answer, the reasoning and where that is written down.
Challenge yourself on this topic → Study as cards
The questions
- 1. A regional insurer is finishing an authorisation package for a new claims platform. Assessors have documented three moderate findings, the system owner has drafted mitigation plans, and the chief information security officer wants the programme manager to sign off so the launch date holds. Who may formally accept the residual risk of operating the platform?
- 2. A federal agency wants to adopt a case-management application that a peer agency already runs under a current authorization to operate. The adopting agency will load its own records into the service and has no appetite for repeating the full assessment. Which authorisation decision fits this situation?
- 6. An agency's authorisation for its payroll system expires every three years, and each renewal consumes a quarter of the security team's capacity while telling leadership little that is new in between. The chief information officer asks how the Risk Management Framework intends approval to be sustained instead.
- 8. A retailer's risk team has finished assessing a new point-of-sale platform, weighing threats, vulnerabilities, cost against benefit, and the risk remaining once controls are applied. The team lead asks the security architect what the assessment report is entitled to conclude.
- 24. An architect records a boundary protection control as implemented because a next-generation firewall is deployed with a hardened ruleset. The assessor finds no evidence that the deployed rules behave as designed. Considering the two angles the SP 800-53 Rev. 5 catalogue applies to any control, what is missing?
- 53. A compliance analyst at a regional insurer must confirm that firewall change records and the current rulesets agree with documented policy, with no interruption to claims processing. The engagement letter allows the analyst to review artefacts only, with no interaction with live devices. Which assessment method fits this work?
- 54. An assessment team at a logistics firm has finished a hands-on technical test of the order platform and proposes to drop the document and configuration review to save budget. The chief information security officer resists. Which two statements support keeping the examination work? Choose two.
- 55. A bank's board wants to learn how far an intruder could get before the security operations centre reacts, so the exercise must run while operations staff remain unaware of it. The assessors ask what has to be in place before they begin. Which condition governs this kind of exercise?
- 56. During an authorised penetration test of a retailer's payment portal, the assessors gain a shell on a web host and immediately find stored credentials for a second server they had never enumerated. Which action matches the staged methodology they are following?
- 57. A vulnerability scan of a hospital's intranet returns findings ranked by the scanning product's own severity labels. Management proposes to publish that ranked list as the organisation's statement of risk. Which two objections should the assessment lead raise? Choose two.
- 58. Midway through an authorised assessment, a tester judges that a denial-of-service check falling outside the signed document would expose a serious weakness in a customer portal. The engagement is time-boxed and the sponsor who signed is travelling. How should the tester proceed?
- 59. An energy utility is standing up an information security continuous monitoring programme and already maintains a current inventory of the systems it owns. To deliver the remaining aims of such a programme, which two capabilities must it add? Choose two.
- 60. A government contractor runs the same exhaustive assessment procedures against a public brochure website and against a system holding claimant medical records. Auditors report that the programme misapplies its own guidance. Which change brings the programme into line?
- 61. A programme manager schedules the security control assessment for a new claims system as a single event in the week before the authorisation decision, arguing that any earlier assessment would examine an unfinished system. The assessment lead pushes back. Which correction should the lead offer?
- 62. A risk assessment of an acquisition target reports several high-likelihood exposures, and the assessors close their briefing by recommending that the board abandon the deal. The chief risk officer objects to how the assessors framed their role. Which statement explains that objection?
- 64. Ransomware is confirmed on three file servers, and the response team has isolated all three. Management asks the team to state how large the incident is before recovery planning begins. Which action best establishes the true scope of the incident?
- 69. An adversary edits the endpoint detection agent's configuration and deletes the log forwarding pipeline, so alerts stop reaching the security operations centre and analysts can no longer trust their consoles. In the current MITRE ATT&CK Enterprise matrix of fifteen tactics, which tactic describes this behaviour?
- 76. While mapping findings against the OWASP Top 10:2025, an application team looks for the XML External Entities category it tracked in earlier editions and finds the category gone. Its document parser still resolves external entity references by default. Where does the 2025 list account for this weakness?
- 363. An assessment plan proposes only automated scanning. Which three assessment methods does SP 800-115 recognise, and what distinguishes them? Choose three.
- 364. An assessor asks whether a documented procedure or an individual employee can be an assessment object. What does SP 800-115 say?
- 365. An assessment programme has phases for planning and execution but stops when the findings list is produced. Which three activities does SP 800-115 place in the post-execution phase? Choose three.
- 366. Into which three families does SP 800-115 sort its technical assessment techniques?
- 367. Which activities does SP 800-115 count among review techniques? Choose three.
- 368. A team wants to enumerate live hosts, the services they expose and the weaknesses those services may carry. Which family of SP 800-115 techniques covers this work, and how is it usually performed?
- 369. Which techniques does SP 800-115 place in the target vulnerability validation family? Choose three.
- 370. An organisation buys an annual penetration test and performs no other technical assessment. Which two points from SP 800-115 argue against relying on one technique? Choose two.
- 371. A team assumes examinations never affect the environment. Which exception does SP 800-115 identify, and why?
- 372. A scoping discussion asks how much operational disruption the organisation will accept from testing. What does SP 800-115 advise?
- 373. An organisation replaces its document and configuration reviews with an expanded programme of technical testing. Which weakness does SP 800-115 say it will now miss?
- 374. A board asks why a clean penetration test report does not mean the organisation is secure. Which two reasons does SP 800-115 give? Choose two.
- 375. An external test begins before any scanning takes place. Which three sources does SP 800-115 describe reconnaissance drawing on? Choose three.
- 376. An organisation wants to understand what damage a contractor with network access could cause. Which testing viewpoint does SP 800-115 describe for this?
- 377. Which two benefits does SP 800-115 attribute to overt testing performed with the knowledge of the organisation's technology staff? Choose two.
- 378. A team plans covert testing and asks whose approval is required. What does SP 800-115 specify?
- 379. During a covert test the organisation's operations team detects unusual activity. What arrangement does SP 800-115 describe to keep that from escalating into a real incident response?
- 380. A sponsor expects a covert test to deliver a complete inventory of the organisation's vulnerabilities. Which two corrections does SP 800-115 support? Choose two.
- 381. Which four phases does SP 800-115 use for penetration testing, and what is unusual about the ordering?
- 382. A client asks what technical work happens during the planning phase of a penetration test. What does SP 800-115 say?
- 383. Which two halves make up the discovery phase of a penetration test in SP 800-115? Choose two.
- 384. A tester records that a web server runs a particular product version by reading what the service returns on connection. What is this technique called, and which enumeration methods are generally available only from inside?
- 385. A penetration test's discovery phase includes searching discarded paperwork and walking through the client's offices. Is this within the scope SP 800-115 describes?
- 386. A tester supplements automated scanning with manual vulnerability analysis. Which trade-off does SP 800-115 describe?
- 387. Which findings does SP 800-115 say a vulnerability scanner can produce? Choose three.
- 388. A scanning programme produces shallow results and the team is considering credentialed scanning. What does SP 800-115 say about that approach?
- 389. A tester plans to rely on unusual scan types to slip past the client's perimeter filtering. What does SP 800-115 caution?
- 390. Which three benefits does SP 800-115 attribute to a documented, repeatable assessment methodology? Choose three.
- 391. An agency schedules its security control testing every eighteen months. What frequency does federal law require, as cited in SP 800-115?
- 392. A team asks which single assessment methodology NIST requires them to adopt. What does SP 800-115 say?
- 393. Which activities does SP 800-115 give as examples of non-technical assessment techniques? Choose two.
- 394. A manager suggests that a thorough testing programme can substitute for implementing several costly controls. How does SP 800-115 frame the purpose of testing and examination?
- 395. An assessor asks what distinguishes the three assessment methods in SP 800-53A from the objects being assessed. What is the distinction?
- 396. Which four kinds of assessment object does SP 800-53A define?
- 397. An assessor argues that locks, keypads and fireproof safes cannot be assessment objects because they contain no code. What does SP 800-53A say?
- 398. Two assessments examine the same control. One inspects three sample servers very thoroughly; the other inspects fifty servers superficially. Which attributes does SP 800-53A use to describe this difference?
- 399. Why does SP 800-53A tie each determination statement to the wording of the control it assesses?
- 400. Who uses the findings produced by applying an assessment procedure, and for what decision?
- 401. An assessor wants to record a determination statement as partially satisfied because most of the control is in place. What does SP 800-53A allow?
- 402. An assessor could not obtain the evidence needed to judge a determination statement before the assessment window closed. How should this be recorded under SP 800-53A?
- 403. An organisation wants its assessment reports to distinguish a minor documentation gap from a control that is entirely absent. What does SP 800-53A permit?
- 404. Why does SP 800-53A place organisation-defined parameters first among a control's determination statements?
- 405. On which counts does SP 800-53A judge the strength of a component's security functionality? Choose three.
- 406. A product is deployed in millions of systems worldwide. What does SP 800-53A observe about assessing the product itself rather than each deployment?
- 407. Match the third-party assessment body to its niche as SP 800-53A describes them. Which pairings are correct? Choose three.
- 408. A vendor supplies only a high-level design summary for a product under development. What does SP 800-53A say this limits?
- 409. Which steps make up the continuous monitoring cycle in NIST SP 800-137? Choose three.
- 410. An agency writes its continuous monitoring strategy solely around individual systems. What does NIST SP 800-137 expect?