CISSP Domain 6: Security Assessment and Testing
Domain 6.0: Security Assessment and Testing · 12% of the exam
Proving that controls work: all 5 objectives (6.1–6.5), from designing and validating an assessment strategy through the ten named testing techniques including the two added in 2024, the process data that turns point-in-time findings into a continuous picture, analysis and reporting that changes something, and audits that produce an opinion rather than a suggestion.
All study guides, current and every new one.
- Interactive online guide
- Downloadable PDF
- Lifetime updates
- 30-day money-back guarantee
Secure checkout via Stripe · no account needed · instant access
12% of your exam score
Domain 6.0 is worth 12% of the CISSP exam. Walk in having mastered it, not hoping it doesn't come up.
Every objective, nothing extra
Built line by line from the official ISC2 CISSP objectives 6.1–6.5: 18 in-depth topics with worked scenarios and exam tips, in a 87-page guide you'll actually finish.
60 exam-style questions
Every question comes with instant feedback and a full explanation, so a wrong answer teaches you as much as a right one.
The cert that changes what you're paid
CISSP is the management-track credential for security: five years of experience to hold it, eight domains wide, and the one most senior security job descriptions name by itself.
Serving, transitioning, or a military spouse?
CISSP appears in the DoD 8140 qualification matrix. See how it maps to work roles, which credentialing program your branch runs, and what it will and will not pay for. Read the DoD 8140 guide →
Read a real excerpt, free
This is the actual opening of Module 6.1, Assessment & audit strategy, not marketing copy. If you like how it teaches, the rest of the guide reads the same way.
Design and validate assessment, test, and audit strategies
Who assesses, how often, over what scope, and whether the strategy actually produces assurance about the things that matter.
Grant Ellery joined Aurora as assessment and audit manager and asked one question of the previous three years of testing: what did we learn that we did not already know? The answer was almost nothing. The same external firm had tested the same twelve internet-facing hosts each year, found the same class of low-severity findings, and produced a report that went into a folder. Meanwhile the customs platform, the terminal OT network and three cloud accounts had never been assessed at all.
That is a testing programme, not an assessment strategy. The difference is the subject of this objective.
Who assesses
| Source | Strengths | Limitations and use |
|---|---|---|
| Internal | Cheap, frequent, deep environmental knowledge, findings actionable immediately. | Not independent, so results carry limited weight externally. Best for continuous control testing and pre-audit readiness. |
| External | Independent perspective, current attacker technique, no organizational blind spots. | Costly, time-boxed, limited context. Best for periodic depth on high-value systems and for validating internal findings. |
| Third-party | Independence formally established; the only form generally accepted as evidence by customers, regulators and certification bodies. | Governed by the standard's rules — a PCI QSA, an ISO certification body, a SOC 2 auditor. Scope and method are set by the scheme, not by you. |
When a stem asks who should perform an assessment, the answer usually turns on the required independence. Evidence for an external party normally requires third-party assessment; validating a control before an audit is internal work; testing the effectiveness of an internal team's own designs requires someone who did not design them. Nobody assesses their own work is the underlying rule.
Location: on-premises, cloud and hybrid
| Environment | What is testable | Constraints |
|---|---|---|
| On-premises | Everything you own: network, hosts, applications, physical controls. | Availability risk from active testing, particularly on OT. Requires change control and a rollback plan. |
| Cloud | Your configuration, your workloads, your identities, your data. Not the provider's infrastructure. | Provider terms govern what testing is permitted; some tests need notification or are prohibited outright. Shared responsibility defines scope: assess the provider through their attestations, and assess your own configuration directly and continuously. |
| Hybrid | Both, plus the connections between them — which is where the interesting findings are. | The identity plane and the network paths joining the two are frequently outside both the on-premises scope and the cloud scope, and therefore tested by nobody. |
Designing the strategy
| Decision | How to make it |
|---|---|
| Scope | Driven by the risk register and asset criticality, not by what is convenient or already instrumented. Every material system should appear on a multi-year plan. |
| Frequency | Matched to rate of change and criticality: continuous for cloud configuration, per-release for applications under active development, annual for stable systems, plus event-triggered assessment after significant change. |
| Depth | From automated scanning through configuration review to full penetration testing and red teaming. Depth follows value at risk. |
| Rules of engagement | Agreed in writing before testing: scope boundaries, permitted techniques, testing windows, escalation contacts, handling of discovered data, and an explicit stop condition. Written authorization protects the tester and the organization. |
| Evidence handling | Findings often contain exploitable detail and real data; treat reports as Restricted and control their distribution. |
| Independence | Proportionate to the assurance required and to who will rely on it. |
Not ready to buy? Read it later.
We'll email you a free sample of this guide as a PDF, no purchase needed.
Try 3 sample questions
Pulled straight from the guide's 60-question bank. Tap an answer for instant feedback and the explanation.
From module 6.1 · Assessment & audit strategy
1. An organization tests the same twelve internet-facing hosts annually and finds the same low-severity issues each time, while its highest-value platform has never been assessed. What is the failure?
From module 6.2 · Security controls testing
1. What distinguishes a penetration test from a vulnerability assessment?
From module 6.3 · Collecting security process data
1. Which indicator provides early warning that risk is increasing before a loss occurs?
57 more questions like these are waiting inside.
What's inside
- 18 in-depth topics across 5 modules, mapped to objectives 6.1–6.5
- 60 exam-style practice questions with instant feedback
- Full answer key explaining why every distractor is wrong
- Breach attack simulation and compliance checks, new in the 2024 outline
- SOC 2 Type I against Type II, and what to read in one
- Complete CISSP acronym & key-term reference
- 87-page downloadable PDF for offline study and printing
- Lifetime updates as the exam evolves
The modules, mapped to the objectives
- 6.112 Qs
Assessment & audit strategy
Design and validate assessment, test, and audit strategies
Internal, external & third-partyIndependence & objectivityOn-premises, cloud & hybrid scopeRules of engagementCoverage against risk profileValidating the strategy itself - 6.212 Qs
Security controls testing
Conduct security controls testing
Vulnerability assessment vs. penetration testingBlack, white & grey boxRed, blue, purple & white teamsSAST, DAST & IASTMisuse cases & coverage analysisBreach attack simulation - 6.312 Qs
Collecting security process data
Collect security process data (e.g., technical and administrative)
Account management metricsManagement review & approval evidenceKPIs vs. KRIsBackup restore verificationAwareness behaviour metricsDR/BC exercise data - 6.412 Qs
Analyzing output & reporting
Analyze test output and generate report
Validation & false positivesRisk-based prioritisationAudience-appropriate reportingRemediation tracking & retestException handlingEthical disclosure - 6.512 Qs
Conducting security audits
Conduct or facilitate security audits
Audit vs. assessmentThe audit lifecycleAuditor independence & reporting lineEvidence hierarchyFacilitating an auditSOC 2 Type I vs. Type II

About the author
Chris Rees
Professional information technologist with 25+ years in IT and the author of 51 certification training courses, 50+ live on Pluralsight, rated 4.6/5 across more than 2,000 reviews. This guide is that same exam-focused teaching, in a format you can finish.
More about ChrisSitting the whole exam? Get the Complete CISSP Collection.
Every domain of the exam, including this guide, for $129, one time.
See everything insideQuestions, answered
Do I need an account to buy?
No. Checkout is a single Stripe form: email and card, about 30 seconds. We create your access from your checkout email automatically and sign you in the moment payment completes.
Is this up to date with the real CISSP exam?
Yes. The guide is mapped module-by-module to the official ISC2 CISSP objectives (6.1–6.5), and lifetime updates are included, so as the exam evolves your guide does too.
What exactly do I get?
Instant access to the interactive online guide with all 60 practice questions, plus a 87-page PDF you can download, print, and keep forever.
Do I need the other domains too?
This guide covers Domain 6.0 (12% of the exam). To prepare for the whole exam, the Complete CISSP Collection bundles all 8 domains for $129, less than the price of three guides.
What if it isn't for me?
Every purchase comes with a 30-day money-back guarantee. Email us and we'll refund you, no hoops.
Who wrote it?
Chris Rees, a professional information technologist with 25+ years in IT and the author of 51 certification courses published on Pluralsight, rated 4.6/5 across 2,007 ratings.
Be ready for 12% of the exam, for $24.95
Instant access, lifetime updates, and a 30-day money-back guarantee. The only risk is walking into the exam without it.
Get the guide