Security Assessment Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Assessment flashcards as text
Which phase of a penetration test involves gathering publicly available information about the target without directly interacting with its systems?
Answer: Passive reconnaissance
Passive reconnaissance (OSINT) collects information from public sources like WHOIS, DNS records, and social media without sending traffic to the target.
A CISSP is reviewing an assessment report that lists 200 vulnerabilities. Which approach should the organization prioritize?
Answer: Prioritize based on risk score combining exploitability, impact, and asset criticality
Effective remediation prioritizes vulnerabilities by combining exploitability likelihood, potential business impact, and the criticality of the affected asset.
During a social engineering assessment, a tester calls an employee pretending to be from IT support and convinces them to reset their password. What type of attack does this represent?
Answer: Vishing
Vishing (voice phishing) uses telephone calls to manipulate victims into revealing sensitive information or performing actions that compromise security.
What does the term 'attack surface' represent in the context of security assessments?
Answer: The total set of entry points an attacker can use to compromise a system
The attack surface encompasses all exposed interfaces, APIs, services, and pathways through which unauthorized access could be gained.
An organization conducts quarterly vulnerability scans but has never performed a penetration test. What critical gap does this create?
Answer: Scans identify weaknesses but cannot demonstrate the actual exploitability or chained attack paths
Penetration tests validate whether identified vulnerabilities are actually exploitable and reveal multi-step attack chains that scanners cannot simulate.
Which concept describes the practice of re-scanning or retesting systems after remediation to confirm vulnerabilities have been successfully addressed?
Answer: Verification testing
Verification testing (also called remediation verification) confirms that patching or configuration changes have successfully closed the identified vulnerabilities.
What is the key difference between a security audit and a security assessment?
Answer: Audits measure compliance against defined standards; assessments evaluate overall security posture and risk
Security audits verify adherence to specific standards or policies, while assessments take a broader view to identify risks, gaps, and improvement opportunities.