Skip to content
ISC2 CISSP · CISSP

CISSP Domain 6: Security Assessment and Testing

Domain 6.0: Security Assessment and Testing · 12% of the exam

Proving that controls work: all 5 objectives (6.1–6.5), from designing and validating an assessment strategy through the ten named testing techniques including the two added in 2024, the process data that turns point-in-time findings into a continuous picture, analysis and reporting that changes something, and audits that produce an opinion rather than a suggestion.

5 modules · 18 topics 87-page PDF 60 practice questions
Read a free sample By the author of 51 Pluralsight courses · 4.6/5 from 2,007 ratings
Best value
$29/ month

All study guides, current and every new one.

or own the whole exam
$129one-time · all 8 domains
or just this guide
$24.95one-time · lifetime access
  • Interactive online guide
  • Downloadable PDF
  • Lifetime updates
  • 30-day money-back guarantee

Secure checkout via Stripe · no account needed · instant access

12% of your exam score

Domain 6.0 is worth 12% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.

Every objective, nothing extra

Built line by line from the official ISC2 CISSP objectives 6.1–6.5: 18 in-depth topics with worked scenarios and exam tips, in a 87-page guide you'll actually finish.

60 exam-style questions

Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.

The cert that changes what you're paid

CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.

Serving, transitioning, or a military spouse?

CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →

Read a real excerpt, free

This is the actual opening of Module 6.1, Assessment & audit strategy, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.

Objective 6.1

Design and validate assessment, test, and audit strategies

Who assesses, how often, over what scope, and whether the strategy actually produces assurance about the things that matter.

Grant Ellery joined Aurora as assessment and audit manager and asked one question of the previous three years of testing: what did we learn that we did not already know? The answer was almost nothing. The same external firm had tested the same twelve internet-facing hosts each year, found the same class of low-severity findings, and produced a report that went into a folder. Meanwhile the customs platform, the terminal OT network and three cloud accounts had never been assessed at all.

That is a testing programme, not an assessment strategy. The difference is the subject of this objective.

Who assesses

SourceStrengthsLimitations and use
InternalCheap, frequent, deep environmental knowledge, findings actionable immediately.Not independent, so results carry limited weight externally. Best for continuous control testing and pre-audit readiness.
ExternalIndependent perspective, current attacker technique, no organizational blind spots.Costly, time-boxed, limited context. Best for periodic depth on high-value systems and for validating internal findings.
Third-partyIndependence formally established; the only form generally accepted as evidence by customers, regulators and certification bodies.Governed by the standard's rules — a PCI QSA, an ISO certification body, a SOC 2 auditor. Scope and method are set by the scheme, not by you.
Exam focus · Independence is the discriminator

When a stem asks who should perform an assessment, the answer usually turns on the required independence. Evidence for an external party normally requires third-party assessment; validating a control before an audit is internal work; testing the effectiveness of an internal team's own designs requires someone who did not design them. Nobody assesses their own work is the underlying rule.

Location: on-premises, cloud and hybrid

EnvironmentWhat is testableConstraints
On-premisesEverything you own: network, hosts, applications, physical controls.Availability risk from active testing, particularly on OT. Requires change control and a rollback plan.
CloudYour configuration, your workloads, your identities, your data. Not the provider's infrastructure.Provider terms govern what testing is permitted; some tests need notification or are prohibited outright. Shared responsibility defines scope: assess the provider through their attestations, and assess your own configuration directly and continuously.
HybridBoth, plus the connections between them — which is where the interesting findings are.The identity plane and the network paths joining the two are frequently outside both the on-premises scope and the cloud scope, and therefore tested by nobody.

Designing the strategy

DecisionHow to make it
ScopeDriven by the risk register and asset criticality, not by what is convenient or already instrumented. Every material system should appear on a multi-year plan.
FrequencyMatched to rate of change and criticality: continuous for cloud configuration, per-release for applications under active development, annual for stable systems, plus event-triggered assessment after significant change.
DepthFrom automated scanning through configuration review to full penetration testing and red teaming. Depth follows value at risk.
Rules of engagementAgreed in writing before testing: scope boundaries, permitted techniques, testing windows, escalation contacts, handling of discovered data, and an explicit stop condition. Written authorization protects the tester and the organization.
Evidence handlingFindings often contain exploitable detail and real data; treat reports as Restricted and control their distribution.
IndependenceProportionate to the assurance required and to who will rely on it.
The guide continues for 87 pagesKeep reading: unlock the full guide

Not ready to buy? Read it later.

We'll email you a free sample of this guide as a PDF, no purchase needed.

Try 3 sample questions

Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.

From module 6.1 · Assessment & audit strategy

  1. 1. An organization tests the same twelve internet-facing hosts annually and finds the same low-severity issues each time, while its highest-value platform has never been assessed. What is the failure?

From module 6.2 · Security controls testing

  1. 1. What distinguishes a penetration test from a vulnerability assessment?

From module 6.3 · Collecting security process data

  1. 1. Which indicator provides early warning that risk is increasing before a loss occurs?

57 more questions like these are waiting inside.

What's inside

  • 18 in-depth topics across 5 modules, mapped to objectives 6.1–6.5
  • 60 exam-style practice questions with instant feedback
  • Full answer key explaining why every distractor is wrong
  • Breach attack simulation and compliance checks, new in the 2024 outline
  • SOC 2 Type I against Type II, and what to read in one
  • Complete CISSP acronym & key-term reference
  • 87-page downloadable PDF for offline study and printing
  • Lifetime updates as the exam evolves

The modules, mapped to the objectives

  1. 6.1

    Assessment & audit strategy

    Design and validate assessment, test, and audit strategies

    12 Qs
    Internal, external & third-partyIndependence & objectivityOn-premises, cloud & hybrid scopeRules of engagementCoverage against risk profileValidating the strategy itself
  2. 6.2

    Security controls testing

    Conduct security controls testing

    12 Qs
    Vulnerability assessment vs. penetration testingBlack, white & grey boxRed, blue, purple & white teamsSAST, DAST & IASTMisuse cases & coverage analysisBreach attack simulation
  3. 6.3

    Collecting security process data

    Collect security process data (e.g., technical and administrative)

    12 Qs
    Account management metricsManagement review & approval evidenceKPIs vs. KRIsBackup restore verificationAwareness behaviour metricsDR/BC exercise data
  4. 6.4

    Analyzing output & reporting

    Analyze test output and generate report

    12 Qs
    Validation & false positivesRisk-based prioritisationAudience-appropriate reportingRemediation tracking & retestException handlingEthical disclosure
  5. 6.5

    Conducting security audits

    Conduct or facilitate security audits

    12 Qs
    Audit vs. assessmentThe audit lifecycleAuditor independence & reporting lineEvidence hierarchyFacilitating an auditSOC 2 Type I vs. Type II
Chris Rees

About the author

Chris Rees

Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.

More about Chris
All 8 CISSP domains

Sitting the whole exam? Get the Complete CISSP Collection.

Every domain of the exam, including this guide, for $129, one time.

See everything inside

Questions, answered

Do I need an account to buy?

No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.

Is this up to date with the real CISSP exam?

Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (6.1–6.5), and lifetime updates are included, so as the exam evolves your guide does too.

What exactly do I get?

Instant access to the interactive online guide with all 60 practice questions, plus a 87-page PDF you can download, print, and keep forever.

Do I need the other domains too?

This guide covers Domain 6.0 (12% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.

What if it isn't for me?

Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.

Who wrote it?

Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.

Be ready for 12% of the exam, for $24.95

Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.

Get the guide

Share this guide