CompTIA Security+ SY0-701 Audits and Assessments Practice Test 2

 

Topic 27 Practice Test 2 covers Audits and Assessments for CompTIA Security+ SY0-701 and maps to objective 5.5: Explain types and purposes of audits and assessments. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To demonstrate exploitable attack paths and impact, which security approach should be selected?

  1. Offensive penetration test
  2. Independent third-party audit
  3. Defensive assessment
  4. Partially known environment test

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. That makes it the best answer here; Partially known environment test addresses assessment in which testers receive limited knowledge similar to a user or partner perspective, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. The question is not asking for this function. It is testing security test focused on emulating attacker techniques to find and exploit weaknesses, so Offensive penetration test is the stronger fit.

Answer C is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. That concept can be valid in another scenario, but this question is testing security test focused on emulating attacker techniques to find and exploit weaknesses; Offensive penetration test therefore fits the requirement more directly.

Answer D is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The scenario instead requires security test focused on emulating attacker techniques to find and exploit weaknesses, which is why Offensive penetration test is the better answer; this option serves the different function defined above.

 

Question 2

Which term describes exercise combining offensive and defensive elements to evaluate end-to-end security capability?

  1. Offensive penetration test
  2. Integrated assessment
  3. Physical penetration test
  4. Passive reconnaissance

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. This matches the requirement as written. Physical penetration test can be valid in another context, but it is used for authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Incorrect Answers

 

Answer A is incorrect because Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses. The scenario instead requires exercise combining offensive and defensive elements to evaluate end-to-end security capability, which is why Integrated assessment is the better answer; this option serves the different function defined above.

Answer C is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The question is not asking for this function. It is testing exercise combining offensive and defensive elements to evaluate end-to-end security capability, so Integrated assessment is the stronger fit.

Answer D is incorrect because Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected. This could be appropriate elsewhere, but the required function is exercise combining offensive and defensive elements to evaluate end-to-end security capability; that makes Integrated assessment the precise choice.

 

Question 3

Which term describes security test focused on emulating attacker techniques to find and exploit weaknesses?

  1. Known-environment test
  2. Physical penetration test
  3. Offensive penetration test
  4. Defensive assessment

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. That makes it the best answer here; Known-environment test addresses assessment in which testers receive extensive information about systems, architecture, or credentials, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. The key mismatch is functional: Offensive penetration test addresses security test focused on emulating attacker techniques to find and exploit weaknesses, the need stated by the question.

Answer B is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The question is not asking for this function. It is testing security test focused on emulating attacker techniques to find and exploit weaknesses, so Offensive penetration test is the stronger fit.

Answer D is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The key mismatch is functional: Offensive penetration test addresses security test focused on emulating attacker techniques to find and exploit weaknesses, the need stated by the question.

 

Question 4

Reviewers working through an assurance and assessment planning exercise identify three separate needs: assessment performed by an external party that is not responsible for operating the controls being reviewed; authorized attempt to bypass physical controls such as locks, badges, or facility procedures; security test focused on emulating attacker techniques to find and exploit weaknesses. Which THREE choices map to those needs? Choose THREE.

  1. Physical penetration test
  2. Independent third-party audit
  3. Defensive assessment
  4. Partially known environment test
  5. Self-assessment
  6. Offensive penetration test

Correct Answers: A, B, F

Correct Answers

 

 

Answer A is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures. It belongs in the fixed-count answer set because it covers one of the stated requirements. Self-assessment instead serves an evaluation performed by the team or organization responsible for the controls and cannot replace this function.

Answer B is correct because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed. This option satisfies a specific requirement in the stem; Defensive assessment serves exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness and therefore is not interchangeable with it.

Answer F is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. This option satisfies a specific requirement in the stem; Defensive assessment serves exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness and therefore is not interchangeable with it.

Incorrect Answers

 

Answer C is incorrect because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The scenario calls for Independent third-party audit, Offensive penetration test, Physical penetration test. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective. The required choices are Independent third-party audit, Offensive penetration test, Physical penetration test. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Self-assessment means an evaluation performed by the team or organization responsible for the controls. The required choices are Independent third-party audit, Offensive penetration test, Physical penetration test. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 5

Two requirements remain open in an assurance and assessment planning exercise: exercise combining offensive and defensive elements to evaluate end-to-end security capability; assessment in which testers begin with little or no internal knowledge. Which TWO options close those specific gaps? Choose TWO.

  1. Internal compliance audit
  2. Offensive penetration test
  3. Integrated assessment
  4. Audit committee
  5. Unknown-environment test

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. The fixed-count item needs this function in the answer set. Audit committee covers a governance body that oversees audit, financial reporting, controls, or related assurance activities, a different requirement.

Answer E is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. The fixed-count item needs this function in the answer set. Audit committee covers a governance body that oversees audit, financial reporting, controls, or related assurance activities, a different requirement.

Incorrect Answers

 

Answer A is incorrect because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. The scenario calls for Integrated assessment, Unknown-environment test. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses. Every answer slot must map to a stated requirement. The correct set is Integrated assessment, Unknown-environment test, so this option cannot replace one of those selections.

Answer D is incorrect because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. The question requires exactly 2 selections: Integrated assessment, Unknown-environment test. This option falls outside that required set. For example, Integrated assessment is required for exercise combining offensive and defensive elements to evaluate end-to-end security capability.

 

Question 6

The control set for an assurance and assessment planning exercise must address both exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness and assessment in which testers receive limited knowledge similar to a user or partner perspective. Which TWO choices map directly to those needs? Choose TWO.

  1. Audit committee
  2. Partially known environment test
  3. Defensive assessment
  4. Self-assessment
  5. Internal compliance audit

Correct Answers: B, C

Correct Answers

 

 

Answer B is correct because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective. This option satisfies a specific requirement in the stem; Audit committee serves a governance body that oversees audit, financial reporting, controls, or related assurance activities and therefore is not interchangeable with it.

Answer C is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. One required function is exactly what this option provides. Audit committee may be useful elsewhere, but it is used for a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

 

Answer A is incorrect because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. The fixed-count answer set is Defensive assessment, Partially known environment test; this option does not fill one of those named functions.

Answer D is incorrect because Self-assessment means an evaluation performed by the team or organization responsible for the controls. The required choices are Defensive assessment, Partially known environment test. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. The scenario calls for Defensive assessment, Partially known environment test. Selecting this option would leave one of those required functions uncovered.

 

Question 7

Which term describes assessment performed by an external party that is not responsible for operating the controls being reviewed?

  1. Independent third-party audit
  2. Self-assessment
  3. Physical penetration test
  4. Integrated assessment

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed. That is the function the question is testing. Integrated assessment would instead be used for exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Incorrect Answers

 

Answer B is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. The concept is valid, but it does not match this stem. The required function is assessment performed by an external party that is not responsible for operating the controls being reviewed, which maps to Independent third-party audit.

Answer C is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. That concept can be valid in another scenario, but this question is testing assessment performed by an external party that is not responsible for operating the controls being reviewed; Independent third-party audit therefore fits the requirement more directly.

Answer D is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. The question is not asking for this function. It is testing assessment performed by an external party that is not responsible for operating the controls being reviewed, so Independent third-party audit is the stronger fit.

 

Question 8

To balance realism and efficiency with some contextual information, which security approach should be selected?

  1. Physical penetration test
  2. Offensive penetration test
  3. Partially known environment test
  4. Audit committee

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective. That is the function the question is testing. Audit committee would instead be used for a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

 

Answer A is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. The question is not asking for this function. It is testing assessment in which testers receive limited knowledge similar to a user or partner perspective, so Partially known environment test is the stronger fit.

Answer B is incorrect because Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses. The scenario instead requires assessment in which testers receive limited knowledge similar to a user or partner perspective, which is why Partially known environment test is the better answer; this option serves the different function defined above.

Answer D is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The key mismatch is functional: Partially known environment test addresses assessment in which testers receive limited knowledge similar to a user or partner perspective, the need stated by the question.

 

Question 9

To test both attack paths and the organization’s ability to detect and respond, which security approach should be selected?

  1. Audit committee
  2. Integrated assessment
  3. Internal compliance audit
  4. Defensive assessment

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. That is the function the question is testing. Internal compliance audit would instead be used for an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

 

Answer A is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The scenario instead requires exercise combining offensive and defensive elements to evaluate end-to-end security capability, which is why Integrated assessment is the better answer; this option serves the different function defined above.

Answer C is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. This could be appropriate elsewhere, but the required function is exercise combining offensive and defensive elements to evaluate end-to-end security capability; that makes Integrated assessment the precise choice.

Answer D is incorrect because Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. That concept can be valid in another scenario, but this question is testing exercise combining offensive and defensive elements to evaluate end-to-end security capability; Integrated assessment therefore fits the requirement more directly.

 

Question 10

Which term describes information gathering that directly interacts with target systems or networks?

  1. Passive reconnaissance
  2. Active reconnaissance
  3. Regulatory examination
  4. Partially known environment test

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Active reconnaissance means information gathering that directly interacts with target systems or networks. The requirement maps directly to this function, whereas Regulatory examination is aimed at formal review performed under the authority of a regulator.

Incorrect Answers

 

Answer A is incorrect because Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected. This could be appropriate elsewhere, but the required function is information gathering that directly interacts with target systems or networks; that makes Active reconnaissance the precise choice.

Answer C is incorrect because Regulatory examination refers to formal review performed under the authority of a regulator. The concept is valid, but it does not match this stem. The required function is information gathering that directly interacts with target systems or networks, which maps to Active reconnaissance.

Answer D is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The scenario instead requires information gathering that directly interacts with target systems or networks, which is why Active reconnaissance is the better answer; this option serves the different function defined above.

 

Question 11

Which term describes authorized attempt to bypass physical controls such as locks, badges, or facility procedures?

  1. Partially known environment test
  2. Unknown-environment test
  3. Physical penetration test
  4. Internal compliance audit

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures. This matches the requirement as written. Internal compliance audit can be valid in another context, but it is used for an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

 

Answer A is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The key mismatch is functional: Physical penetration test addresses authorized attempt to bypass physical controls such as locks, badges, or facility procedures, the need stated by the question.

Answer B is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. The question is not asking for this function. It is testing authorized attempt to bypass physical controls such as locks, badges, or facility procedures, so Physical penetration test is the stronger fit.

Answer D is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. The question is not asking for this function. It is testing authorized attempt to bypass physical controls such as locks, badges, or facility procedures, so Physical penetration test is the stronger fit.

 

Question 12

An architect working on an assurance and assessment planning exercise needs one capability that provides formal review performed under the authority of a regulator and another that provides assessment performed by an external party that is not responsible for operating the controls being reviewed. Which TWO selections are the best match? Choose TWO.

  1. Independent third-party audit
  2. Partially known environment test
  3. Known-environment test
  4. Regulatory examination
  5. Integrated assessment

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed. This selection maps directly to one of the named needs. Known-environment test addresses assessment in which testers receive extensive information about systems, architecture, or credentials, so it does not satisfy the same slot.

Answer D is correct because Regulatory examination means formal review performed under the authority of a regulator. This option satisfies a specific requirement in the stem; Known-environment test serves assessment in which testers receive extensive information about systems, architecture, or credentials and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective. The required choices are Regulatory examination, Independent third-party audit. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials. Every answer slot must map to a stated requirement. The correct set is Regulatory examination, Independent third-party audit, so this option cannot replace one of those selections.

Answer E is incorrect because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. The scenario calls for Regulatory examination, Independent third-party audit. Selecting this option would leave one of those required functions uncovered.

 

Question 13

To measure how well defenders identify and handle malicious activity, which security approach should be selected?

  1. Known-environment test
  2. Active reconnaissance
  3. Defensive assessment
  4. Independent third-party audit

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The requirement maps directly to this function, whereas Active reconnaissance is aimed at information gathering that directly interacts with target systems or networks.

Incorrect Answers

 

Answer A is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. The scenario instead requires exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, which is why Defensive assessment is the better answer; this option serves the different function defined above.

Answer B is incorrect because Active reconnaissance refers to information gathering that directly interacts with target systems or networks. The question is not asking for this function. It is testing exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, so Defensive assessment is the stronger fit.

Answer D is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. The key mismatch is functional: Defensive assessment addresses exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness, the need stated by the question.

 

Question 14

Two requirements remain open in an assurance and assessment planning exercise: exercise combining offensive and defensive elements to evaluate end-to-end security capability; information gathering performed without directly interacting with the target systems in a way likely to be detected. Which TWO options close those specific gaps? Choose TWO.

  1. Defensive assessment
  2. Passive reconnaissance
  3. Unknown-environment test
  4. Active reconnaissance
  5. Integrated assessment

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected. The fixed-count item needs this function in the answer set. Unknown-environment test covers assessment in which testers begin with little or no internal knowledge, a different requirement.

Answer E is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. It belongs in the fixed-count answer set because it covers one of the stated requirements. Active reconnaissance instead serves information gathering that directly interacts with target systems or networks and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. The fixed-count answer set is Integrated assessment, Passive reconnaissance; this option does not fill one of those named functions. For example, Passive reconnaissance is required for information gathering performed without directly interacting with the target systems in a way likely to be detected.

Answer C is incorrect because Unknown-environment test means assessment in which testers begin with little or no internal knowledge. Every answer slot must map to a stated requirement. The correct set is Integrated assessment, Passive reconnaissance, so this option cannot replace one of those selections.

Answer D is incorrect because Active reconnaissance means information gathering that directly interacts with target systems or networks. The required choices are Integrated assessment, Passive reconnaissance. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 15

To identify control gaps before or independent of an external examination, which security approach should be selected?

  1. Physical penetration test
  2. Known-environment test
  3. Independent third-party audit
  4. Internal compliance audit

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements. This is the precise fit for the scenario. Physical penetration test serves the different purpose of authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Incorrect Answers

 

Answer A is incorrect because Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures. This could be appropriate elsewhere, but the required function is an audit performed by or for the organization to evaluate adherence to its own and external requirements; that makes Internal compliance audit the precise choice.

Answer B is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. The question is not asking for this function. It is testing an audit performed by or for the organization to evaluate adherence to its own and external requirements, so Internal compliance audit is the stronger fit.

Answer C is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. The key mismatch is functional: Internal compliance audit addresses an audit performed by or for the organization to evaluate adherence to its own and external requirements, the need stated by the question.

 

Question 16

Which governance body oversees audit, financial reporting, controls, or related assurance activities?

  1. Independent third-party audit
  2. Self-assessment
  3. Internal compliance audit
  4. Audit committee

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. The requirement maps directly to this function, whereas Self-assessment is aimed at an evaluation performed by the team or organization responsible for the controls.

Incorrect Answers

 

Answer A is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. That concept can be valid in another scenario, but this question is testing a governance body that oversees audit, financial reporting, controls, or related assurance activities; Audit committee therefore fits the requirement more directly.

Answer B is incorrect because Self-assessment refers to an evaluation performed by the team or organization responsible for the controls. The concept is valid, but it does not match this stem. The required function is a governance body that oversees audit, financial reporting, controls, or related assurance activities, which maps to Audit committee.

Answer C is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. The concept is valid, but it does not match this stem. The required function is a governance body that oversees audit, financial reporting, controls, or related assurance activities, which maps to Audit committee.

 

Question 17

Which term describes formal review performed under the authority of a regulator?

  1. Integrated assessment
  2. Audit committee
  3. Known-environment test
  4. Regulatory examination

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Regulatory examination means formal review performed under the authority of a regulator. This matches the requirement as written. Known-environment test can be valid in another context, but it is used for assessment in which testers receive extensive information about systems, architecture, or credentials.

Incorrect Answers

 

Answer A is incorrect because Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability. The scenario instead requires formal review performed under the authority of a regulator, which is why Regulatory examination is the better answer; this option serves the different function defined above.

Answer B is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The key mismatch is functional: Regulatory examination addresses formal review performed under the authority of a regulator, the need stated by the question.

Answer C is incorrect because Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials. That concept can be valid in another scenario, but this question is testing formal review performed under the authority of a regulator; Regulatory examination therefore fits the requirement more directly.

 

Question 18

To determine whether the organization meets binding regulatory expectations, which security approach should be selected?

  1. Regulatory examination
  2. Internal compliance audit
  3. Independent third-party audit
  4. Audit committee

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Regulatory examination means formal review performed under the authority of a regulator. This is the precise fit for the scenario. Audit committee serves the different purpose of a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

 

Answer B is incorrect because Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements. The question is not asking for this function. It is testing formal review performed under the authority of a regulator, so Regulatory examination is the stronger fit.

Answer C is incorrect because Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed. The question is not asking for this function. It is testing formal review performed under the authority of a regulator, so Regulatory examination is the stronger fit.

Answer D is incorrect because Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities. The concept is valid, but it does not match this stem. The required function is formal review performed under the authority of a regulator, which maps to Regulatory examination.

 

Question 19

An architect working on an assurance and assessment planning exercise needs one capability that provides exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness and another that provides exercise combining offensive and defensive elements to evaluate end-to-end security capability. Which TWO selections are the best match? Choose TWO.

  1. Self-assessment
  2. Active reconnaissance
  3. Integrated assessment
  4. Audit committee
  5. Defensive assessment

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability. This option satisfies a specific requirement in the stem; Active reconnaissance serves information gathering that directly interacts with target systems or networks and therefore is not interchangeable with it.

Answer E is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness. One required function is exactly what this option provides. Active reconnaissance may be useful elsewhere, but it is used for information gathering that directly interacts with target systems or networks.

Incorrect Answers

 

Answer A is incorrect because Self-assessment means an evaluation performed by the team or organization responsible for the controls. The question requires exactly 2 selections: Defensive assessment, Integrated assessment. This option falls outside that required set. For example, Integrated assessment is required for exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer B is incorrect because Active reconnaissance means information gathering that directly interacts with target systems or networks. The scenario calls for Defensive assessment, Integrated assessment. Selecting this option would leave one of those required functions uncovered. For example, Defensive assessment is required for exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer D is incorrect because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities. Every answer slot must map to a stated requirement. The correct set is Defensive assessment, Integrated assessment, so this option cannot replace one of those selections.

 

Question 20

To discover live services and technical details with greater detection risk, which security approach should be selected?

  1. Unknown-environment test
  2. Active reconnaissance
  3. Regulatory examination
  4. Partially known environment test

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Active reconnaissance means information gathering that directly interacts with target systems or networks. The requirement maps directly to this function, whereas Partially known environment test is aimed at assessment in which testers receive limited knowledge similar to a user or partner perspective.

Incorrect Answers

 

Answer A is incorrect because Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge. The question is not asking for this function. It is testing information gathering that directly interacts with target systems or networks, so Active reconnaissance is the stronger fit.

Answer C is incorrect because Regulatory examination refers to formal review performed under the authority of a regulator. This could be appropriate elsewhere, but the required function is information gathering that directly interacts with target systems or networks; that makes Active reconnaissance the precise choice.

Answer D is incorrect because Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective. The concept is valid, but it does not match this stem. The required function is information gathering that directly interacts with target systems or networks, which maps to Active reconnaissance.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!