Security Assessment and Testing
CISSP · 36 questions
- A city CISO asks the internal security and audit teams to design ongoing tests of IAM and network controls that the organization itself will execute under city authority. What are they primarily building?
- Leadership hires an outside firm to review the city access-control policy implementation for gaps, without requesting a formal regulated attestation report. Which assessment type best fits?
- The city parking-payment platform must satisfy card-brand expectations with an independent assessor's formal report. Which strategy element is essential?
- An assessment strategy covers only the on-premises CAD servers and ignores cloud email and hybrid identity integrations. What design flaw does that reveal?
- A county runs vulnerability scans on rapidly changing cloud citizen apps only once per year. Risk and change rate are both high. What should leadership conclude about the assessment strategy?
- A city CIO must choose assessors for the annual review of the tax-collection system and wants both independence and deep knowledge of legacy workflows. Which approach best balances those tradeoffs?
- Quarterly authenticated scanning of the county property-appraisal system reports missing OS and application patches. What is the primary security-assessment purpose of that activity?
- A municipality is launching a new online payments portal and wants an exercise that both attacks and improves detection simultaneously. Which team model best fits that goal?
- Domain-controller privileged logons for the school-district directory have gone unreviewed for months. Which testing activity should the security manager add first?
- After a change window, the housing authority needs continuous proof that resident-portal MFA still completes successfully. Which testing approach best provides that assurance?
- Custom fee-calculator code for city building permits is about to release. What should security assessment include before production?
- Testers validating the park-and-recreation permit site only exercise successful purchase paths. What should they add to strengthen security testing?
- A vendor claims the library catalog API is 'fully tested,' but cannot show which security suites or paths were exercised. What should the city demand?
- The city's 311 mobile app exposes a citizen UI, backend APIs, and network entry points. How should security testing be scoped across those surfaces?
- Transit IT wants ongoing proof that SIEM detections fire for common attacker techniques against fare systems. Which control-testing approach fits best?
- Card payment terminals at the municipal recreation center must meet PCI-aligned hardening rules. What assessment activity confirms systems still match required baselines?
- Leadership reviews only automated vulnerability-scan scores for the courts case-management system and calls the program a full penetration test. What correction should the assessor make?
- A water utility plans penetration testing near pressure-control PLCs. What scoping principle is most important?
- The county identity team needs management-visible evidence about joiner-mover-leaver health. Which process data should assessment collect?
- The CISO prepares a quarterly pack for the city manager on security-program health. Which data best serves as key performance and risk indicators?
- The public-works backup dashboard shows nightly job success, yet nobody has restored a sample lately. What process data is still missing for assurance?
- After mandatory cyber awareness for city employees, leadership asks whether behavior improved. Which metrics should be collected?
- After a tabletop on courthouse continuity, what process data most improves BC/DR maturity for the next cycle?
- SOC analysts compile rich security process metrics that never leave the operations drawer. What is required for those metrics to fulfill their assessment purpose?
- A vulnerability report for the business-license portal lists CVSS scores but no owners or deadlines. What must reporting add to drive remediation?
- A critical library catalog finding will not be fixed this quarter due to a vendor dependency. How should that decision be handled?
- An independent researcher privately reports a flaw in the city permit portal. What process should the city follow?
- Assessment results for the emergency-dispatch network must inform both the city council and the engineering team. How should reports be tailored?
- Scanner output for the tax-assessor web farm is flooded with noise, and analysts fear real issues are buried. What analysis step is required?
- Developers report that a high-severity finding on the utility billing API is fixed. What should happen before the finding is closed?
- A city CIO asks internal audit to review IT general controls for the finance ERP before year-end. What should that engagement primarily evaluate?
- External financial auditors for a county ask for evidence that IT controls affecting the CAFR reporting path are operating. What is the security team's best facilitation focus?
- A transit authority must satisfy a federal grant condition that requires an independent security audit of fare-collection systems. Which approach best meets that requirement?
- A municipal hybrid estate runs voter-registration data in a cloud SaaS tenant and legacy case files in an on-premises data center. What should an enterprise security audit scope include?
- County security leads want audits to stop becoming last-minute fire drills. What practice best prepares teams for efficient facilitation?
- A city CISO contrasts an annual independent audit of payroll ITGCs with the SOC's weekly vulnerability scans. What distinction best explains their different purposes?