CompTIA Security+ SY0-701 Audits and Assessments Practice Test 1

 

Topic 27 Practice Test 1 covers Audits and Assessments for CompTIA Security+ SY0-701 and maps to objective 5.5: Explain types and purposes of audits and assessments. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

A review during an assurance and assessment planning exercise identifies two gaps. One requires governance body that oversees audit, financial reporting, controls, or related assurance activities. The other requires authorized attempt to bypass physical controls such as locks, badges, or facility procedures. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Physical penetration test
  2. Independent third-party audit
  3. Audit committee
  4. Integrated assessment
  5. Offensive penetration test

Correct Answers: A, C

Correct Answers

 

 

Answer A is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The fixed-count item needs this function in the answer set. Integrated assessment covers exercise combining offensive and defensive elements to evaluate end-to-end security capability, a different requirement.

Answer C is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. This option satisfies a specific requirement in the stem; Offensive penetration test serves security test focused on emulating attacker techniques to find and exploit weaknesses and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed. Every answer slot must map to a stated requirement. The correct set is Audit committee, Physical penetration test, so this option cannot replace one of those selections.

Answer D is incorrect because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. The required choices are Audit committee, Physical penetration test. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. The question requires exactly 2 selections: Audit committee, Physical penetration test. This option falls outside that required set.

 

Question 2

An organization commissions an assessment of its compliance with its own policies and applicable external requirements. The assessment is performed by or for the organization itself. Which audit type is this?

  1. Internal compliance audit
  2. Unknown-environment test
  3. Regulatory examination
  4. Passive reconnaissance

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. That is the function the question is testing. Passive reconnaissance would instead be used for information gathering performed without directly interacting with the target systems in a way likely to be detected.

Incorrect Answers

 

Answer B is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. The question is not asking for this function. It is testing an audit performed by or for the organization to evaluate adherence to its own and external requirements, so Internal compliance audit is the stronger fit.

Answer C is incorrect because Regulatory examination refers to formal review performed under the authority of a regulator. The concept is valid, but it does not match this stem. The required function is an audit performed by or for the organization to evaluate adherence to its own and external requirements, which maps to Internal compliance audit.

Answer D is incorrect because Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected. This could be appropriate elsewhere, but the required function is an audit performed by or for the organization to evaluate adherence to its own and external requirements; that makes Internal compliance audit the precise choice.

 

Question 3

To collect public or third-party information while minimizing direct contact, which security approach should be selected?

  1. Passive reconnaissance
  2. Independent third-party audit
  3. Defensive assessment
  4. Internal compliance audit

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. This is the precise fit for the scenario. Internal compliance audit serves the different purpose of an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

 

Answer B is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. That concept can be valid in another scenario, but this question is testing information gathering performed without directly interacting with the target systems in a way likely to be detected; Passive reconnaissance therefore fits the requirement more directly.

Answer C is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The concept is valid, but it does not match this stem. The required function is information gathering performed without directly interacting with the target systems in a way likely to be detected, which maps to Passive reconnaissance.

Answer D is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. This could be appropriate elsewhere, but the required function is information gathering performed without directly interacting with the target systems in a way likely to be detected; that makes Passive reconnaissance the precise choice.

 

Question 4

A review during an assurance and assessment planning exercise identifies two gaps. One requires audit performed by or for the organization to evaluate adherence to its own and external requirements. The other requires exercise combining offensive and defensive elements to evaluate end-to-end security capability. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Self-assessment
  2. Internal compliance audit
  3. Regulatory examination
  4. Offensive penetration test
  5. Integrated assessment

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. The fixed-count item needs this function in the answer set. Offensive penetration test covers security test focused on emulating attacker techniques to find and exploit weaknesses, a different requirement.

Answer E is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. This option satisfies a specific requirement in the stem; Regulatory examination serves formal review performed under the authority of a regulator and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because Self-assessment means an evaluation performed by the team or organization responsible for the controls. The question requires exactly 2 selections: Integrated assessment, Internal compliance audit. This option falls outside that required set. For example, Internal compliance audit is required for an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Answer C is incorrect because Regulatory examination means formal review performed under the authority of a regulator. The fixed-count answer set is Integrated assessment, Internal compliance audit; this option does not fill one of those named functions. For example, Integrated assessment is required for exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer D is incorrect because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. The fixed-count answer set is Integrated assessment, Internal compliance audit; this option does not fill one of those named functions.

 

Question 5

To identify readiness and gaps using internal knowledge at relatively low cost, which security approach should be selected?

  1. Self-assessment
  2. Physical penetration test
  3. Active reconnaissance
  4. Independent third-party audit

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Self-assessment means an evaluation performed by the team or organization responsible for the controls. That is the function the question is testing. Active reconnaissance would instead be used for information gathering that directly interacts with target systems or networks.

Incorrect Answers

 

Answer B is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The concept is valid, but it does not match this stem. The required function is an evaluation performed by the team or organization responsible for the controls, which maps to Self-assessment.

Answer C is incorrect because Active reconnaissance refers to information gathering that directly interacts with target systems or networks. The concept is valid, but it does not match this stem. The required function is an evaluation performed by the team or organization responsible for the controls, which maps to Self-assessment.

Answer D is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. The question is not asking for this function. It is testing an evaluation performed by the team or organization responsible for the controls, so Self-assessment is the stronger fit.

 

Question 6

The control set for an assurance and assessment planning exercise must address both authorized attempt to bypass physical controls such as locks, badges, or facility procedures and assessment in which testers begin with little or no internal knowledge. Which TWO choices map directly to those needs? Choose TWO.

  1. Unknown-environment test
  2. Known-environment test
  3. Regulatory examination
  4. Offensive penetration test
  5. Physical penetration test

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. This option satisfies a specific requirement in the stem; Offensive penetration test serves security test focused on emulating attacker techniques to find and exploit weaknesses and therefore is not interchangeable with it.

Answer E is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures. This selection maps directly to one of the named needs. Known-environment test addresses assessment in which testers receive extensive information about systems, architecture, or credentials, so it does not satisfy the same slot.

Incorrect Answers

 

Answer B is incorrect because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials. The scenario calls for Unknown-environment test, Physical penetration test. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Regulatory examination means formal review performed under the authority of a regulator. The question requires exactly 2 selections: Unknown-environment test, Physical penetration test. This option falls outside that required set. For example, Unknown-environment test is required for assessment in which testers begin with little or no internal knowledge.

Answer D is incorrect because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. The question requires exactly 2 selections: Unknown-environment test, Physical penetration test. This option falls outside that required set.

 

Question 7

Which evaluation is performed by the team or organization responsible for the controls?

  1. Regulatory examination
  2. Defensive assessment
  3. Self-assessment
  4. Integrated assessment

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Self-assessment means an evaluation performed by the team or organization responsible for the controls. That is the function the question is testing. Defensive assessment would instead be used for exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Incorrect Answers

 

Answer A is incorrect because Regulatory examination refers to formal review performed under the authority of a regulator. This could be appropriate elsewhere, but the required function is an evaluation performed by the team or organization responsible for the controls; that makes Self-assessment the precise choice.

Answer B is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The question is not asking for this function. It is testing an evaluation performed by the team or organization responsible for the controls, so Self-assessment is the stronger fit.

Answer D is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. This could be appropriate elsewhere, but the required function is an evaluation performed by the team or organization responsible for the controls; that makes Self-assessment the precise choice.

 

Question 8

Senior governance members need independent oversight of audit findings and the progress of corrective actions. Which body is responsible for this oversight?

  1. Known-environment test
  2. Defensive assessment
  3. Physical penetration test
  4. Audit committee

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. That is the function the question is testing. Known-environment test would instead be used for assessment in which testers receive extensive information about systems, architecture, or credentials.

Incorrect Answers

 

Answer A is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. The scenario instead requires a governance body that oversees audit, financial reporting, controls, or related assurance activities, which is why Audit committee is the better answer; this option serves the different function defined above.

Answer B is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The concept is valid, but it does not match this stem. The required function is a governance body that oversees audit, financial reporting, controls, or related assurance activities, which maps to Audit committee.

Answer C is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. This could be appropriate elsewhere, but the required function is a governance body that oversees audit, financial reporting, controls, or related assurance activities; that makes Audit committee the precise choice.

 

Question 9

Which term describes information gathering performed without directly interacting with the target systems in a way likely to be detected?

  1. Audit committee
  2. Passive reconnaissance
  3. Defensive assessment
  4. Unknown-environment test

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. That makes it the best answer here; Defensive assessment addresses exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The key mismatch is functional: Passive reconnaissance addresses information gathering performed without directly interacting with the target systems in a way likely to be detected, the need stated by the question.

Answer C is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The question is not asking for this function. It is testing information gathering performed without directly interacting with the target systems in a way likely to be detected, so Passive reconnaissance is the stronger fit.

Answer D is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. The scenario instead requires information gathering performed without directly interacting with the target systems in a way likely to be detected, which is why Passive reconnaissance is the better answer; this option serves the different function defined above.

 

Question 10

Two requirements remain open in an assurance and assessment planning exercise: exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness; information gathering performed without directly interacting with the target systems in a way likely to be detected. Which TWO options close those specific gaps? Choose TWO.

  1. Audit committee
  2. Offensive penetration test
  3. Defensive assessment
  4. Active reconnaissance
  5. Passive reconnaissance

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. It belongs in the fixed-count answer set because it covers one of the stated requirements. Audit committee instead serves a governance body that oversees audit, financial reporting, controls, or related assurance activities and cannot replace this function.

Answer E is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. It belongs in the fixed-count answer set because it covers one of the stated requirements. Audit committee instead serves a governance body that oversees audit, financial reporting, controls, or related assurance activities and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. The scenario calls for Defensive assessment, Passive reconnaissance. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. The required choices are Defensive assessment, Passive reconnaissance. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Active reconnaissance means information gathering that directly interacts with target systems or networks. The scenario calls for Defensive assessment, Passive reconnaissance. Selecting this option would leave one of those required functions uncovered. For example, Passive reconnaissance is required for information gathering performed without directly interacting with the target systems in a way likely to be detected.

 

Question 11

Two requirements remain open in an assurance and assessment planning exercise: security test focused on emulating attacker techniques to find and exploit weaknesses; information gathering that directly interacts with target systems or networks. Which TWO options close those specific gaps? Choose TWO.

  1. Active reconnaissance
  2. Offensive penetration test
  3. Passive reconnaissance
  4. Internal compliance audit
  5. Self-assessment

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Active reconnaissance means information gathering that directly interacts with target systems or networks. This option satisfies a specific requirement in the stem; Self-assessment serves an evaluation performed by the team or organization responsible for the controls and therefore is not interchangeable with it.

Answer B is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. It belongs in the fixed-count answer set because it covers one of the stated requirements. Internal compliance audit instead serves an audit performed by or for the organization to evaluate adherence to its own and external requirements and cannot replace this function.

Incorrect Answers

 

Answer C is incorrect because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. The required choices are Offensive penetration test, Active reconnaissance. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. The question requires exactly 2 selections: Offensive penetration test, Active reconnaissance. This option falls outside that required set.

Answer E is incorrect because Self-assessment means an evaluation performed by the team or organization responsible for the controls. The required choices are Offensive penetration test, Active reconnaissance. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 12

To provide independent oversight of audit findings and remediation, which security approach should be selected?

  1. Offensive penetration test
  2. Audit committee
  3. Self-assessment
  4. Partially known environment test

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. That makes it the best answer here; Self-assessment addresses an evaluation performed by the team or organization responsible for the controls, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses. The concept is valid, but it does not match this stem. The required function is a governance body that oversees audit, financial reporting, controls, or related assurance activities, which maps to Audit committee.

Answer C is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. The key mismatch is functional: Audit committee addresses a governance body that oversees audit, financial reporting, controls, or related assurance activities, the need stated by the question.

Answer D is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The key mismatch is functional: Audit committee addresses a governance body that oversees audit, financial reporting, controls, or related assurance activities, the need stated by the question.

 

Question 13

Which term describes exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness?

  1. Defensive assessment
  2. Passive reconnaissance
  3. Partially known environment test
  4. Active reconnaissance

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. That makes it the best answer here; Active reconnaissance addresses information gathering that directly interacts with target systems or networks, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected. The scenario instead requires exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, which is why Defensive assessment is the better answer; this option serves the different function defined above.

Answer C is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The question is not asking for this function. It is testing exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, so Defensive assessment is the stronger fit.

Answer D is incorrect because Active reconnaissance refers to information gathering that directly interacts with target systems or networks. That concept can be valid in another scenario, but this question is testing exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness; Defensive assessment therefore fits the requirement more directly.

 

Question 14

Which term describes assessment in which testers receive extensive information about systems, architecture, or credentials?

  1. Active reconnaissance
  2. Known-environment test
  3. Independent third-party audit
  4. Defensive assessment

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials. The requirement maps directly to this function, whereas Independent third-party audit is aimed at assessment performed by an external party that is not responsible for operating the controls being reviewed.

Incorrect Answers

 

Answer A is incorrect because Active reconnaissance refers to information gathering that directly interacts with target systems or networks. The key mismatch is functional: Known-environment test addresses assessment in which testers receive extensive information about systems, architecture, or credentials, the need stated by the question.

Answer C is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. This could be appropriate elsewhere, but the required function is assessment in which testers receive extensive information about systems, architecture, or credentials; that makes Known-environment test the precise choice.

Answer D is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. This could be appropriate elsewhere, but the required function is assessment in which testers receive extensive information about systems, architecture, or credentials; that makes Known-environment test the precise choice.

 

Question 15

Which audit is performed by or for the organization to evaluate adherence to its own and external requirements?

  1. Self-assessment
  2. Defensive assessment
  3. Integrated assessment
  4. Internal compliance audit

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. The requirement maps directly to this function, whereas Self-assessment is aimed at an evaluation performed by the team or organization responsible for the controls.

Incorrect Answers

 

Answer A is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. This could be appropriate elsewhere, but the required function is an audit performed by or for the organization to evaluate adherence to its own and external requirements; that makes Internal compliance audit the precise choice.

Answer B is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The key mismatch is functional: Internal compliance audit addresses an audit performed by or for the organization to evaluate adherence to its own and external requirements, the need stated by the question.

Answer C is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. The concept is valid, but it does not match this stem. The required function is an audit performed by or for the organization to evaluate adherence to its own and external requirements, which maps to Internal compliance audit.

 

Question 16

To perform deep testing efficiently with broad internal knowledge, which security approach should be selected?

  1. Offensive penetration test
  2. Unknown-environment test
  3. Known-environment test
  4. Self-assessment

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials. That is the function the question is testing. Self-assessment would instead be used for an evaluation performed by the team or organization responsible for the controls.

Incorrect Answers

 

Answer A is incorrect because Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses. The key mismatch is functional: Known-environment test addresses assessment in which testers receive extensive information about systems, architecture, or credentials, the need stated by the question.

Answer B is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. This could be appropriate elsewhere, but the required function is assessment in which testers receive extensive information about systems, architecture, or credentials; that makes Known-environment test the precise choice.

Answer D is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. That concept can be valid in another scenario, but this question is testing assessment in which testers receive extensive information about systems, architecture, or credentials; Known-environment test therefore fits the requirement more directly.

 

Question 17

During an assurance and assessment planning exercise, three requirements must be addressed: (1) audit performed by or for the organization to evaluate adherence to its own and external requirements; (2) governance body that oversees audit, financial reporting, controls, or related assurance activities; and (3) formal review performed under the authority of a regulator. Which THREE choices best satisfy them? Choose THREE.

  1. Unknown-environment test
  2. Integrated assessment
  3. Regulatory examination
  4. Audit committee
  5. Passive reconnaissance
  6. Internal compliance audit

Correct Answers: C, D, F

Correct Answers

 

 

Answer C is correct because Regulatory examination means formal review performed under the authority of a regulator. This option satisfies a specific requirement in the stem; Unknown-environment test serves assessment in which testers begin with little or no internal knowledge and therefore is not interchangeable with it.

Answer D is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. This selection maps directly to one of the named needs. Unknown-environment test addresses assessment in which testers begin with little or no internal knowledge, so it does not satisfy the same slot.

Answer F is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. It belongs in the fixed-count answer set because it covers one of the stated requirements. Unknown-environment test instead serves assessment in which testers begin with little or no internal knowledge and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. The question requires exactly 3 selections: Internal compliance audit, Audit committee, Regulatory examination. This option falls outside that required set.

Answer B is incorrect because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. The required choices are Internal compliance audit, Audit committee, Regulatory examination. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. The fixed-count answer set is Internal compliance audit, Audit committee, Regulatory examination; this option does not fill one of those named functions.

 

Question 18

To simulate an external attacker who must discover the environment, which security approach should be selected?

  1. Audit committee
  2. Offensive penetration test
  3. Integrated assessment
  4. Unknown-environment test

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. That makes it the best answer here; Offensive penetration test addresses security test focused on emulating attacker techniques to find and exploit weaknesses, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The question is not asking for this function. It is testing assessment in which testers begin with little or no internal knowledge, so Unknown-environment test is the stronger fit.

Answer B is incorrect because Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses. The key mismatch is functional: Unknown-environment test addresses assessment in which testers begin with little or no internal knowledge, the need stated by the question.

Answer C is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. The concept is valid, but it does not match this stem. The required function is assessment in which testers begin with little or no internal knowledge, which maps to Unknown-environment test.

 

Question 19

Which term describes assessment in which testers begin with little or no internal knowledge?

  1. Defensive assessment
  2. Unknown-environment test
  3. Internal compliance audit
  4. Known-environment test

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. This matches the requirement as written. Internal compliance audit can be valid in another context, but it is used for an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

 

Answer A is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The concept is valid, but it does not match this stem. The required function is assessment in which testers begin with little or no internal knowledge, which maps to Unknown-environment test.

Answer C is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. That concept can be valid in another scenario, but this question is testing assessment in which testers begin with little or no internal knowledge; Unknown-environment test therefore fits the requirement more directly.

Answer D is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. The question is not asking for this function. It is testing assessment in which testers begin with little or no internal knowledge, so Unknown-environment test is the stronger fit.

 

Question 20

To test whether an attacker could gain unauthorized physical access, which security approach should be selected?

  1. Self-assessment
  2. Unknown-environment test
  3. Physical penetration test
  4. Integrated assessment

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The requirement maps directly to this function, whereas Integrated assessment is aimed at exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Incorrect Answers

 

Answer A is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. The question is not asking for this function. It is testing authorized attempt to bypass physical controls such as locks, badges, or facility procedures, so Physical penetration test is the stronger fit.

Answer B is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. This could be appropriate elsewhere, but the required function is authorized attempt to bypass physical controls such as locks, badges, or facility procedures; that makes Physical penetration test the precise choice.

Answer D is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. That concept can be valid in another scenario, but this question is testing authorized attempt to bypass physical controls such as locks, badges, or facility procedures; Physical penetration test therefore fits the requirement more directly.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!