CISSP DOMAIN 6 SECURITY
ASSESSMENT TESTING
PRACTICE TEST
COMPLETE 150
QUESTIONS
Question 1: A security manager is planning a penetration test of an internet-facing payment portal. What should be established FIRST before active testing begins?
Choices:
1) Rules of engagement that dene scope, authorization, timing, and prohibited actions 2) A public disclosure statement for customers 3) A remediation deadline for every possible nding 4) A list of all production administrator passwords Correct Answer: Rules of engagement that dene scope, authorization, timing, and prohibited actions Explanation: Rules of engagement provide formal authorization and dene the boundaries, timing, contacts, and prohibited techniques for the test. They reduce legal and operational risk before intrusive activity starts.Page 1
Question 2: An organization wants the greatest auditor independence when
evaluating controls operated by its own security department. Which approach is BEST?
Choices:
1) Ask the system administrator to certify compliance 2) Use an independent third-party assessor with no operational responsibility for the controls 3) Have the control owners audit their own work 4) Use an internal auditor who reports to the security manager Correct Answer: Use an independent third-party assessor with no operational responsibility for the controls Explanation: An independent third-party assessor has the least operational conict of interest and generally provides the strongest independence when evaluating controls run by the organization.
Question 3: A company has limited budget but needs frequent reviews of routine
security controls. Which assessment strategy is MOST practical?
Choices:
1) Rely only on vendor marketing attestations 2) Use internal assessments for routine reviews and reserve external specialists for higher- risk or specialized work 3) Stop testing until a full external audit can be funded 4) Use only external assessors for every monthly review Correct Answer: Use internal assessments for routine reviews and reserve external specialists for higher-risk or specialized work Explanation: Internal assessments are cost-eective for frequent routine reviews. External or third-party expertise can then be targeted where independence or specialized skills provide the most value.Page 2
Question 4: Before assessing a SaaS application, what is the MOST important
planning step related to the cloud service provider?
Choices:
1) Assume the provider is responsible for every control 2) Limit the review to the customer user interface 3) Map control responsibilities using the contract and shared-responsibility model 4) Disable all provider logging to avoid duplicate evidence Correct Answer: Map control responsibilities using the contract and shared-responsibility model Explanation: Cloud assessments must identify which controls are operated by the customer and which by the provider. Contracts and the shared-responsibility model dene the assessment boundary and evidence sources.Question 5: A penetration test could disrupt a fragile production system. What is the BEST risk treatment during test planning?
Choices:
1) Dene safe test methods, maintenance windows, backups, and stop conditions in the rules of engagement 2) Exclude the system permanently from all assurance activities 3) Allow testers to decide during exploitation whether an outage is acceptable 4) Run the most aggressive tests without notice Correct Answer: Dene safe test methods, maintenance windows, backups, and stop conditions in the rules of engagement Explanation: Fragile systems require explicit safeguards such as approved techniques, timing, recovery readiness, and stop conditions. This preserves useful testing while controlling operational risk.Page 3