Browse all practice questions for the CISSP Domain 6 Security Assessment and Testing Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISSP Domain 6 Security Assessment and Testing Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • What aspect does Path Coverage primarily aim to test in a program?
  • What type of testing typically focuses on the user experience without knowledge of the internal workings of the application?
  • What international framework was SSAE-16 based on?
  • What is the primary function of a war dialer?
  • What do system events refer to?
  • Which of the following best describes pen-testing?
  • What is the primary purpose of Application Programming Interfaces (APIs)?
  • Why does compiled code pose more risk than interpreted code?
  • What is the role of formal modeling in security assessments?
  • What method is commonly used to assess how well software testing has covered the potential uses of an application?
  • Why is passive scanning recommended alongside wireless security technologies?
  • What does path coverage aim to ensure during testing?
  • In software development, what does the term ‘verification’ primarily relate to?
  • What is a common method for ensuring internal NTP server synchronization?
  • What is the primary characteristic of passive monitoring?
  • Which testing method requires sufficient test cases for every possible combination of conditions in program decisions?
  • What is Jim's best choice to address the ongoing vulnerability flag from the scanner after applying a patch?
  • What type of testing environment is required for a QA team to ensure complete code coverage, including error conditions?
  • Which aspect of testing can contribute to increased accountability in the organization?
  • What logging standard is widely used by network devices and Linux systems for message logging?
  • What technique is often used in dynamic testing to reveal vulnerabilities like SQL injection?
  • What is the main objective of log management in security systems?
  • Why is it important to conduct positive and negative testing during the assessment of an application?
  • Which type of code review is typically performed by automated tools rather than by a human?
  • Which type of monitoring involves external agents?
  • What role does the reporting phase of a penetration test play in its overall effectiveness?
  • What is indicated by failure audit logs?
  • What is the primary objective of Real User Monitoring (RUM)?
  • What is typically the overall goal of comprehensive assessment and testing strategy?
  • What type of metrics should security managers monitor?
  • What is the key function of misuse case diagrams?
  • Which type of coverage is considered a minimum level for most software products?
  • What type of testing is performed to ensure that separately developed software modules properly exchange data?
  • What is Synthetic Performance Monitoring used for?
  • What technique focuses on analyzing code without executing it?
  • What is the definition of assurance in the context of security?
  • Which of the following is a method utilized in security architecture?
  • What technique does network discovery scanning use to identify systems?
  • In covert security testing, who is unaware of the test being conducted?
  • What can be a consequence of unauthorized access through piggybacking?
  • What does Ring Zero refer to in an operating system?
  • Which ISO standard is associated with quality techniques relevant to security assessment?
  • What does system level testing verify?
  • Which of the following is the best method for quickly identifying systems vulnerable to a newly announced vulnerability?
  • What might indicate a potential security issue based on web traffic?
  • What role do Intrusion Detection Systems (IDS) play in an organization?
  • Which of the following is not a concern for Jim when planning his organization's log management systems?
  • Which scoring system should be used to compare vulnerabilities based on exploitability and remediation difficulty?
  • What is encompassed in Security Log Management?
  • In the context of software, what do use cases illustrate?
  • What factor is NOT considered when scheduling a review of security controls?
  • How can Jennifer ensure that all Windows desktops have identical log settings for the SIEM?
  • What could be a consequence of using outdated password-cracking software during testing?
  • When assessing security mechanisms, what type of assessment object is applied according to NIST standards?
  • What type of assessment report should Lauren request to determine the enforcement of policies over time for a 3rd party service organization?
  • How do automated vulnerability scanners function?
  • Which type of testing verifies that a control is functioning properly?
  • What does maintaining a log size help prevent in security analysis?
  • What does positive testing focus on?
  • What does interface testing specifically validate?
  • Which type of testing ensures quality units are furnished for integration into a final product?
  • What is the purpose of network flow capture in security?
  • What is a major difference between synthetic and passive monitoring?
  • What is the purpose of verification in biometric systems?
  • What type of issues can fuzz testing uncover?
  • What is an important consideration for using NTP Network Time Protocol?
  • When conducting a security audit, which of the following is typically NOT included?
  • What term describes an assessment performed by a third party to evaluate the effectiveness of security controls?
  • Which type of penetration test is Saria's team likely to conduct to expose vulnerabilities realistically?
  • Which best represents the aim of validation in software testing?
  • What term describes the testing that uncovers new bugs introduced by patches or configuration changes?
  • What aspect does data flow coverage emphasize in its testing criteria?
  • What kind of report might a company issue for general assurance on their service operations?
  • Which of the following issues can arise from misconfiguration, logical and functional flaws, and poor programming practices?
  • What is a potential cause of inconsistent time stamps in log files?
  • What is one of the key goals of a penetration test during the reporting phase?
  • What does Real User Monitoring (RUM) aim to analyze?
  • What is the purpose of authenticated scans?
  • What does tampering refer to in data security?
  • What is white-box testing primarily focused on?
  • What protocol is specifically used to manage vulnerability data?
  • While performing active wireless scanning, which issue is least likely to occur?
  • What is the purpose of static source code analysis (SAST)?
  • What is the intent of Real User Monitoring (RUM)?
  • What is a key drawback to relying solely on automated tools for code analysis?
  • Which protocol is typically used for secure communication in network services?
  • What type of report is typically generated during functional testing to indicate test metrics?
  • What does CVE stand for in cybersecurity contexts?
  • Which testing method captures actual user experiences and interactions?
  • Which practice helps in identifying events of interest during log analysis?
  • Which tool is unable to identify a target's operating system for penetration testing?
  • What is the purpose of Positive Testing?
  • What is the primary objective of conducting interface testing?
  • What type of testing is Susan planning to conduct to verify communications and error handling in her e-commerce application?
  • In penetration testing, what should be prioritized when handling discovered vulnerabilities?
  • What does coverage criteria in software testing ensure?
  • What does Negative Testing verify in an application?
  • What is typically the primary goal of penetration testing?
  • Which of the following is not a typical part of a penetration test report?
  • What is the primary purpose of logging in security assessment?
  • What NIST document outlines the procedures for creating an Information Security Continuous Monitoring (ISCM) program?
  • What is the primary focus of integration testing?
  • What best defines architecture security reviews?
  • Which automated tool should Angela use to test a web browser's handling of unexpected data?
  • What does branch coverage specifically assess in software testing?
  • Which tests should include reviews of all user interfaces?
  • What is the primary role of a network's log management system?
  • What is the primary purpose of an intrusion detection system (IDS) during security assessments?
  • What does information disclosure involve?
  • What role do web proxies play in the context of internet access?
  • What is the purpose of conducting architecture security reviews?
  • What role does mutation fuzzing play in security assessment?
  • What is the function of supervisor mode in security systems?
  • What is the purpose of code comparison in software security?
  • The CVE dictionary is primarily used to identify what?
  • How are Bluetooth scans characterized in terms of personal devices?
  • Nikto, Burp Suite, and Wapiti are examples of what type of tools?
  • Which of the following is a challenge in ensuring operational assurance?
  • What system provides metrics and calculation tools for assessing the impact and exploitability of vulnerabilities?
  • What does static testing analyze to evaluate the security of software?
  • Why might a network administrator choose to use TCP Connect scanning?
  • What is the primary purpose of vulnerability scans?
  • In the context of software development, what is the result of effective code coverage analysis?
  • Which of the following is a key aspect of a SOC 3 report Type 2?
  • In log analysis, what is the recommended action if the log size is too small?
  • What does DB monitoring primarily assess?
  • What is a primary benefit of using automated tools in security testing?
  • What is the goal of loop coverage testing?
  • What is the objective of Information Security Continuous Monitoring (ISCM)?
  • What approach can be used to evaluate security measures effectively?
  • Which of the following factors affects the performance of a security control?
  • What does dynamic testing help to identify in a system?
  • What passive monitoring technique records all user interaction with an application or website to ensure quality and performance?
  • What is the focus of integration level testing?
  • What is the significance of a SOC 3 report seal on a website?
  • What type of diagram in application threat modeling captures malicious users and includes mitigations and threats?
  • What type of port scanning is referred to as "half open" scanning?
  • What does verification in the SDLC primarily provide?
  • Which of the following is a primary function of fuzz testing software?
  • During a port scan, what type of devices is likely being discovered if responses are observed on TCP ports 80, 443, 515, and 9100?
  • Why is the archival process important in log management?
  • What do breaches in security primarily aim to compromise?
  • What type of testing detects vulnerabilities that could be exploited by external attackers?
  • What might modified logs indicate?
  • Which of the following is not a method of synthetic transaction monitoring?
  • What is a crucial aspect of interface testing in complex software development?
  • What type of log is generated when a Windows system is rebooted?
  • Which process is considered the foundation of software assessment programs in code reviews?
  • Which of the following accurately describes decision (branch) coverage?
  • In security protocols, what is the significance of bypassing audit and logging functions?
  • Which of the following roles is typically involved in the penetration testing process?
  • What type of measurement is indicated by providing a key performance indicator in relation to vulnerability remediation?
  • Which report is commonly known as SSAE 16?
  • The most formal code review process is known as what?
  • What can be determined from NetFlow regarding network performance?
  • What type of attack did Sari successfully complete by impersonating an officer's assistant to reset a password?
  • What does Synthetic Performance Monitoring utilize?
  • Why might Ben's manager be concerned about the comprehensiveness of the scan?
  • What is the first step that should occur before a penetration test is performed?
  • Which type of SOC report is most appropriate for providing assurance about an organization's security availability?
  • Which type of test helps identify how a system behaves under unusual or incorrect usage scenarios?
  • What does a warning message indicate?
  • Saria is writing a request for proposal for a code review. What type should she specify to ensure consideration of business logic?
  • What type of scanning is called TCP SYN scanning?
  • Which testing method focuses on simulating real-world attacks to assess security?
  • What is spoofing in the context of cybersecurity?
  • During a penetration test, which phase is critical for determining how the findings will be addressed?
  • What is Syslog primarily used for in network environments?
  • What are use cases used for in testing?
  • What function does Vulnerability Management Software serve?
  • Testing that focuses on functions a system should not allow exemplifies which type of testing?
  • What type of testing evaluates code in a runtime environment without requiring access to source code?
  • Which of the following is NOT a concern when using fuzzing to identify program faults?
  • During a security assessment, what is the aim of design and development reviews?
  • What is the most important task during Phase 1 Planning of a penetration test?
  • What is a common goal of penetration testing?
  • What is one of the primary environments for dynamic testing?
  • What does NetFlow enable a network administrator to do?
  • Which types of coverage criteria are commonly used to validate a code testing suite?
  • Which aspect relates to the likelihood that a system will come under attack during security assessments?
  • What does Loop Coverage ensure in software testing?
  • What does elevation of privilege mean in a security context?
  • What test type is associated with validating typical customer behavior in an application through scripted data?
  • What is the purpose of super-zapping?
  • What does synthetic performance monitoring involve?
  • What is a characteristic of authenticated scans compared to unauthenticated ones?
  • Ben's organization is using STRIDE to assess software. Which control is appropriate for addressing an elevation of privilege threat?
  • What aspect does the CVSS system primarily evaluate regarding vulnerabilities?
  • What does passive scanning typically look for?
  • Which flag is not used in TCP SYN scanning?
  • What is the purpose of a SOC 3 report?
  • What is a key focus of the OPSEC process?
  • Which of the following best describes cumulative risk in the context of security assessments?
  • What key performance measure should a team maintain to measure the effectiveness of regression testing on a software patch?
  • Which testing method leverages internal software knowledge to select data?
  • What should be the next step after a vulnerability scan identifies a critical vulnerability on a system?
  • What are use cases primarily used for in software development?
  • What type of devices can passive scanning help identify?
  • What does condition coverage require in software testing?
  • What type of monitoring uses simulated traffic to a website to assess performance?
  • What can monitoring repeat audit findings help a security manager achieve?
  • Which testing technique focuses on evaluating the internal workings of an application?
  • Which system does not natively support logging events via syslog?
  • Which type of code issue is most likely to be missed during testing if analysis is run in a nonproduction environment?
  • What is one of the primary functions of audit records in a security context?
  • What is the purpose of a misuse case in system design?
  • What is a key advantage of non-regression testing?
  • Which type of information can be gathered using NetFlow?
  • What information does a success audit log provide?
  • What information is typically contained in audit records?
  • When is a Code Review Report typically generated?
  • Which tool is most likely to be utilized during the discovery phase of a penetration test?
  • What type of penetration test is conducted when minimal information about the target organization is provided?
  • What does piggybacking refer to?
  • What method can be used to measure the effectiveness of security controls over time?
  • In a penetration test, Jim has agreed to perform a test without prior knowledge or details about the bank. This is referred to as?
  • What distinguishes mutation fuzzing from generational fuzzing?
  • What should Susan do to predict high-risk areas for her organization effectively?
  • What might cause a failure in password-cracking efforts during a wireless network penetration test?
  • When is TCP Connect scanning typically used?
  • What is Threat Modeling focused on?
  • What type of logging should Saria enable on her routers to analyze traffic between network segments?
  • What is the purpose of misuse case testing?
  • What is the primary purpose of threat modeling?
  • What is a common outcome expected from vulnerability assessments?
  • What is the benefit of using threat modeling in software development?
  • Which testing method does NOT require knowledge of the internal workings of a system?
  • Which aspect of application security does static source code analysis primarily focus on?
  • What STRIDE category applies to a transaction identification issue caused by a shared symmetric key among multiple servers?
  • Which NIST Special Publication covers the assessment of security and privacy controls?
  • Receiving a response with both SYN and ACK flags indicates what about a port?
  • What type of review is Kathleen conducting after planning, assigning roles, and preparing materials for a code review?
  • What is a common limitation of automated scanning tools in identifying specific security flaws?
  • What is STRIDE primarily used for?
  • What does SOC 2 focus on?
  • What outcome is desired from conducting security control tests?
  • What is one challenge faced by a Log Management System?
  • Which of the following log entries is typically not generated during normal operations?
  • What type of log entry is generated when a system is rebooted?
  • What is the purpose of conducting mutation testing?
  • What is required for conducting a penetration test?
  • Which coverage method is considered minimum for most software products?
  • What does statement coverage require in software testing?
  • What is a characteristic of static testing?
  • Which of the following security practices can help prevent unauthorized access when conducting penetration tests?
  • What is a crucial concern to address during planning to ensure successful reporting after a penetration test?
  • What is the main objective of white-box testing in software development?
  • What sequence best describes the typical process for building an Information Security Continuous Monitoring program according to NIST SP 800-137?
  • What is SAS 70 focused on?
  • What technology should an organization implement to ensure logs can be time sequenced across the entire infrastructure?
  • Which of the following is not a part of the discovery phase in penetration testing?
  • Which tool is best for scanning services on TCP port 443, commonly associated with HTTPS?
  • What does a port scanner do?
  • What does a SOC 1 report focus on?
  • What kind of reports are service organization control (SOC) reports?
  • During a penetration test, what type of scan is indicated by flags URG, FIN, and PSH being set?
  • What is often a consideration when conducting security assessments of systems?
  • In penetration testing, which condition poses a direct risk to Bluetooth devices?
  • Why is it important to test physical interfaces in software applications?
  • Which of the following best describes breaches in information security?
  • Which of the following techniques is NOT appropriate for preventing or detecting tampering with data?
  • What type of vulnerability scan accesses both configuration and network service information from the system it is run against?
  • What does the presence of modified logs typically suggest in a security context?
  • Which key aspect is involved in safeguarding data integrity during analysis?
  • What type of transactions is Emily using in her testing when she sends a series of expected data to a web application?
  • Which of the following is a function of log analysis in security?
  • What is the meaning of repudiation in cybersecurity?
  • What is the key focus of conducting Threat Modeling?
  • What do the 2011 CWE/SANS Top 25 Most Dangerous Software Errors represent?
  • What type of audit is likely to provide both control and operational effectiveness details?
  • Which of the following tools is typically used for web application vulnerability assessments?
  • What type of monitoring evaluates network layer performance for applications?
  • What type of monitoring does not include user session tracking?
  • What does the term "rogue devices" refer to in passive scanning?
  • What is the focus of Path Coverage in software testing?
  • Nmap is an example of what type of tool?
  • What logging issue might Alex have encountered if Danielle logged into her workstation at 8am and the web application at 3am?
  • What does CSV stand for in data formats?
  • Which of the following choices is not considered a vector for testing a web application's security robustness?
  • What method modifies a program to create small variations and tests these variations for correct behavior?
  • What type of scan should a penetration tester run to identify the most open services when lacking full access to generate raw packets?
  • What characteristic distinguishes dynamic testing from other testing methodologies?
  • After installing additional tools, what phase do penetration testers typically return to?
  • In third-party audits, what should an organization focus on to ensure timely resolution of exceptions?
  • After conducting a penetration test and receiving a port scan result, what should Ben do next?
  • Which testing method focuses on applying invalid or unexpected inputs to validate responses?
  • What does a test coverage report indicate?
  • What is the primary goal of a vulnerability assessment?
  • What is the primary focus of regression testing?
  • What type of fuzzing is Ben conducting if he uses models to create fuzzed data based on application behavior?
  • Which type of testing ensures that the code works as planned without affecting existing functionality?
  • What issue may arise due to improper log handling settings?
  • What essential information is included in an audit trail?
  • What keeps a packet sent during Xmas scanning "lit up like a Christmas tree"?
  • What is the purpose of regression testing in software development?
  • Which backup verification method should Karen avoid to ensure her organization's backups are reliable?
  • What report should Susan request for operating effectiveness details if she has received a SAS-70 Type 1 report?
  • What does operational assurance verify?
  • What is the focus of data flow coverage in testing?
  • Susan needs an open source tool for remote vulnerability scanning. Which tool would meet her requirements?
  • What does Loop Coverage specifically measure in software testing?
  • What is the main goal of conducting code reviews?
  • What is the primary goal of Static Source Code Analysis (SAST)?
  • Why is dynamic testing critical for applications developed by third parties?
  • What benefit do unique user IDs provide when reviewing logs?
  • What type of tool should Alex use to automate filling web application forms to test for format string vulnerabilities?
  • What does proactive monitoring involve in the context of web applications?
  • What type of analysis is useful for assessing ongoing security postures?
  • What valuable information can be derived from audit logging during a security event?
  • Which approach to testing focuses only on the application’s outputs without knowing the internal code?
  • What does regression testing verify?
  • Which of the following options describes the main focus of condition coverage?
  • What characterizes blackbox testing?
  • Which of the following describes the purpose of unit testing?
  • The ability to interact with software through interfaces is provided by?
  • When using Metasploit as part of penetration testing, what can Jim expect?
  • Based on nmap's default scan results, what operating system was most likely running on the scanned system?
  • What does a Code Coverage Report provide information about?
  • What does fuzz testing primarily aim to accomplish?
  • Which of the following is an example of a key metric a security manager might track?
  • Which of the following is not a potential issue with active wireless scanning?
  • Which of the following is not a hazard associated with penetration testing?
  • What does audit logging provide information about?
  • What type of tests may be included in security testing?
  • What services are likely running on ports 21 and 23, which were found open during a port scan?
  • Which testing method requires access to source code and performs a detailed examination of logical paths?
  • What is real user monitoring (RUM) designed to do?
  • The abbreviation NVD stands for what?
  • Which statement best describes overt security testing?
  • Which vulnerability is unlikely to be detected by a web vulnerability scanner?
  • What is the first step in the Fagan inspection process?
  • STRIDE is useful in which part of application threat modeling?
  • What analysis technique involves executing the code and observing its behavior during execution?
  • What is a significant risk if Jim's IT staff need to restore from a backup according to a recent finding?
  • What is the function of web application scanning tools in dynamic testing?
  • What types of problems can future warnings signal in a system?
  • What is the primary goal of negative testing in application security?
  • What is a critical requirement before conducting penetration testing?
  • What role does a vulnerability scanner play in the context of risk management?
  • What is the goal of Multi-Condition Coverage in testing?
  • Why is it important to track the number of software flaws detected during pre-production scanning?
  • In the context of security assessments, what is one of the primary purposes of a fuzz testing tool?
  • What is the purpose of setting a clipping level in security assessments?
  • What method helps in identifying flow data for network security monitoring?
  • What type of vulnerabilities will not be found by a vulnerability scanner?
  • What does a SOC 3 Report Type 1 cover?
  • In which type of testing does a tester know the internal details of the software being tested?
  • How does covert security testing differ from traditional testing approaches?
  • During a penetration test focusing on Bluetooth security, which concern is least relevant for Lauren to address?
  • What does Regression Analysis determine?
  • What does test coverage analysis assess?
  • What does the term attack surface refer to in security?
  • Which type of tool would Alex use to check for vulnerabilities related to the Heartbleed bug?
  • What element is crucial for monitoring network traffic effectively?
  • What does condition coverage require in terms of program decision testing?
  • What is the outcome expected from performing condition coverage?
  • Which concept is related to the transfer of data across interfaces?
  • What is the primary function of an Intrusion Prevention System (IPS)?
  • What is a limitation of statement coverage in testing?
  • Which IT standard is Jim's organization least likely to use in its audits?
  • What type of tool is Jim using when he scans for available services and collects version information through banner grabbing?
  • What does sufficient test case coverage imply in the context of software testing?
  • Which of the following signifies a significant problem in a system?
  • What does validation in software development determine?
  • What perspective does a Misuse Case represent in software design?
  • Which scanning technique involves using flags that signal the different states of a connection?
  • What strategy should be employed to handle a vulnerability identified by a vulnerability scanner?
  • What are the steps involved in a Fagan inspection?
  • During a port scan, what type of system is likely found if TCP and UDP ports 137-139, TCP 445, and TCP 1433 are open?
  • What does a Misuse Case identify in system design?
  • What challenge might Jim face if he conducts a gray box penetration test from offsite with provided RFC 1918 addresses?
  • Which of the following is not typically tested as an interface during the software testing process?
  • What does the term 'compromised accounts' refer to?
  • What does data flow coverage focus on assessing?
  • According to NIST SP 800-53A, which assessment object type is being covered if the assessment includes IPS devices?
  • What does TCP port monitoring indicate?
  • What three potential statuses are provided for a port during an nmap scan?
  • During which stage is unit testing conducted?
  • What does TCP ACK scanning signify when a packet with the ACK flag is sent?
  • MITRE's CVE database provides what type of information?
  • What is tailgating in terms of security controls?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy