Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 67

As part of a security control assessment, which of the following sources of data would provide the MOST direct insight into the effectiveness of security controls?
  • A Results from the latest penetration test or security assessment.
  • B Findings from a recent regulatory compliance audit.
  • C Analysis of past security incidents to identify recurring weaknesses.
  • D Review of user account permissions and recent access control changes.
Reveal correct answer

Correct answer: A

Explanation

OBJ. 6.3 - Security assessments and penetration tests directly evaluate the effectiveness of security controls by simulating real-world attacks and vulnerabilities. While account reviews and incident analysis help identify risks, they do not systematically test control effectiveness. Compliance audits assess adherence to policies but do not guarantee security, as organizations can be compliant yet still vulnerable. Regular security testing ensures that controls function as intended, making it the most valuable input for a security control assessment. For support or reporting issues, include Question ID: 67d96913eac84fca71b27eb4 in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need