CISSP Mastery
All domains
Domain 612% of exam

Security Assessment and Testing

5 lessons ~2h

0%
0/5

Verifying that controls actually work. Covers assessment/test/audit strategy, the full toolbox of control testing (vulnerability scans, pen tests, code review, misuse cases), collecting process data (KPIs/KRIs), reporting with remediation, and internal/external/third-party audits.

Exam tips โ€” what to expect

  • 1Distinguish the activities precisely: a vulnerability assessment finds weaknesses, a penetration test exploits them, and an audit verifies compliance against a standard.
  • 2Remember the audience and scope: assessment reports go to MANAGEMENT in plain language, and an assessment recommends fixes but does NOT perform the remediation.
  • 3Know the tools and report types: Nmap = discovery/port scan, Nessus = vulnerability scan, Metasploit = exploitation; SOC 1/2/3 and Type I (design) vs Type II (design + effectiveness over time).

Lessons

  1. 6.1

    Design and validate assessment, test, and audit strategies

    Plan testing by who performs it and where. Distinguish internal, external, and third-party assessments across on-prem, cloud, and hybrid locations.

    ~20 min

  2. 6.2

    Conduct security control testing

    The core lesson. Know each technique and when to use it: vulnerability assessment vs penetration test (red/blue/purple), log review, synthetic transactions, code review/testing, misuse cases, interface testing, coverage analysis, breach-attack simulation, and compliance checks.

    ~45 min

  3. 6.3

    Collect security process data

    Gather the technical and administrative evidence that proves the program runs: account management, management review, KPIs/KRIs, backup verification, training, and DR/BC data.

    ~25 min

  4. 6.4

    Analyze test output and generate report

    Turn findings into action: remediation, exception handling, and ethical disclosure of vulnerabilities.

    ~20 min

  5. 6.5

    Conduct or facilitate security audits

    Audits validate compliance and effectiveness. Know the internal/external/third-party distinction (e.g., SOC 1/2/3 reports) across deployment locations.

    ~20 min

Domain 6 Exam ยท 50 questions

Complete all 5 lessons above, then take the 50-question exam. Pass at 70% to unlock the next domain.

0/5 lessons done