Cissp Domain 6 Security Assessment Testing Practice Test Complete 150 Questions

Food & Hospitality

CISSP DOMAIN 6 SECURITY ASSESSMENT TESTING PRACTICE TEST COMPLETE 150 QUESTIONS Question 1: A security manager is planning a penetration test of an internet-facing payment portal. What should be es...

Study Guide Viewer

Loading secure 3-page preview…

Study Guide Preview

Extracted text from the free preview pages.

CISSP DOMAIN 6 SECURITY

ASSESSMENT TESTING

PRACTICE TEST

COMPLETE 150

QUESTIONS

Question 1: A security manager is planning a penetration test of an internet-facing payment portal. What should be established FIRST before active testing begins?

Choices:

1) Rules of engagement that de�ne scope, authorization, timing, and prohibited actions 2) A public disclosure statement for customers 3) A remediation deadline for every possible �nding 4) A list of all production administrator passwords Correct Answer: Rules of engagement that de�ne scope, authorization, timing, and prohibited actions Explanation: Rules of engagement provide formal authorization and de�ne the boundaries, timing, contacts, and prohibited techniques for the test. They reduce legal and operational risk before intrusive activity starts.Page 1

Question 2: An organization wants the greatest auditor independence when

evaluating controls operated by its own security department. Which approach is BEST?

Choices:

1) Ask the system administrator to certify compliance 2) Use an independent third-party assessor with no operational responsibility for the controls 3) Have the control owners audit their own work 4) Use an internal auditor who reports to the security manager Correct Answer: Use an independent third-party assessor with no operational responsibility for the controls Explanation: An independent third-party assessor has the least operational con�ict of interest and generally provides the strongest independence when evaluating controls run by the organization.

Question 3: A company has limited budget but needs frequent reviews of routine

security controls. Which assessment strategy is MOST practical?

Choices:

1) Rely only on vendor marketing attestations 2) Use internal assessments for routine reviews and reserve external specialists for higher- risk or specialized work 3) Stop testing until a full external audit can be funded 4) Use only external assessors for every monthly review Correct Answer: Use internal assessments for routine reviews and reserve external specialists for higher-risk or specialized work Explanation: Internal assessments are cost-e�ective for frequent routine reviews. External or third-party expertise can then be targeted where independence or specialized skills provide the most value.Page 2

Question 4: Before assessing a SaaS application, what is the MOST important

planning step related to the cloud service provider?

Choices:

1) Assume the provider is responsible for every control 2) Limit the review to the customer user interface 3) Map control responsibilities using the contract and shared-responsibility model 4) Disable all provider logging to avoid duplicate evidence Correct Answer: Map control responsibilities using the contract and shared-responsibility model Explanation: Cloud assessments must identify which controls are operated by the customer and which by the provider. Contracts and the shared-responsibility model de�ne the assessment boundary and evidence sources.Question 5: A penetration test could disrupt a fragile production system. What is the BEST risk treatment during test planning?

Choices:

1) De�ne safe test methods, maintenance windows, backups, and stop conditions in the rules of engagement 2) Exclude the system permanently from all assurance activities 3) Allow testers to decide during exploitation whether an outage is acceptable 4) Run the most aggressive tests without notice Correct Answer: De�ne safe test methods, maintenance windows, backups, and stop conditions in the rules of engagement Explanation: Fragile systems require explicit safeguards such as approved techniques, timing, recovery readiness, and stop conditions. This preserves useful testing while controlling operational risk.Page 3

Get full access $39.00
Buy Now