CISSP · Domain 6
Security Assessment and Testing
About 12% of the exam
Assessment strategy
- Internal, external, or third-party assessors
- Scope, rules of engagement, authorization in writing
- Risk-based: test what matters most
- Assessment finds, audit attests, test proves
- Untested surfaces stay unknown risks
- Findings need an owner and a deadline
- Verify remediation, then close
- Independence rises with assurance needed
Vulnerability assessment
- Discover assets
- Scan
- Prioritize
- Remediate
- Verify
- Credentialed scan
- logs in, sees installed software
- Uncredentialed scan
- outside view, misses local flaws
- CVSS
- 0 to 10 severity score
- False positive
- flagged, not real
- False negative
- missed, the dangerous one
- Compensating control
- isolate what cannot be patched
Penetration testing
Knowledge given
- Black box
- nothing, outsider view
- Gray box
- some credentials and diagrams
- White box
- full source and architecture
- Double blind
- defenders not told either
Phases
- Plan and scope with rules of engagement
- Reconnaissance and discovery
- Scanning and enumeration
- Exploitation, gain access
- Post-exploitation, pivot, persist
- Report, clean up, retest
Teams
- Red
- attacks, emulates real adversaries
- Blue
- defends, detects, responds
- Purple
- red and blue collaborate live
- White
- referees and scores
Rules of engagement win every dispute: document the finding with proof and move on unless exploitation was authorized
Application testing methods
Static (SAST)
- Reads source or binaries, no execution
- Early in development, in the IDE or build
- Finds injection patterns, hardcoded secrets
- Many false positives to triage
- Blind to runtime configuration
Dynamic (DAST)
- Attacks the running application
- No source needed, black box
- Finds misconfiguration, missing headers
- Later in the cycle, staging
- Limited code coverage
Others
- IAST
- agent inside the app during tests
- RASP
- blocks attacks at runtime
- SCA
- known flaws in third-party components
- Fuzzing
- malformed input, crash hunting
- Symbolic execution
- solve path constraints, deeper reach
- Manual code review
- finds logic flaws tools miss
Test coverage and analysis
- Unit
- one component in isolation
- Integration
- components working together
- Regression
- old features still work
- Misuse case
- test what an attacker would try
- Interface testing
- APIs, UI, boundaries between parts
- Statement coverage
- every line ran once
- Branch coverage
- every decision, both ways
- Mutation testing
- break the code, tests should fail
- Synthetic transactions
- scripted user actions, watch results
- Breach simulation
- automated attack replays
Log review and monitoring
- Synchronize clocks with NTP first
- Centralize in a SIEM, protect from tampering
- Retain per policy and legal hold
- Clipping levels cut noise, set thresholds
- Review privileged and failed logons
- Many failures then success: investigate the success
- UEBA baselines behavior, flags drift
- Log what you will actually review
Logs are evidence only if their integrity and timeline can be defended
Audits and SOC reports
SOC report types
- SOC 1
- controls over financial reporting
- SOC 2
- trust services criteria, restricted
- SOC 3
- public summary of SOC 2
- Type I
- design at a point in time
- Type II
- operating effectiveness over a period
Trust services criteria
- Security: always required, common criteria
- Availability: uptime commitments met
- Processing integrity: complete, accurate, timely
- Confidentiality: restricted data stays restricted
- Privacy: personal data handled as promised
Audit types
- Internal
- own staff, management view
- External
- independent firm, reports to board
- Third-party
- assess a supplier or provider
- ISO 27001
- certification then surveillance audits
- SSAE 18, ISAE 3402
- attestation standards behind SOC
Type II over a period is the one customers want; a clean Type I only says the design looked right that day
Recovery plan testing
- Checklist review
- Walkthrough or tabletop
- Simulation
- Parallel test
- Full interruption
- Least to most disruptive in that order
- Parallel runs the recovery site alongside production
- Full interruption fails over for real
- Purpose: prove procedures and people, not paperwork
- Restore from backup or it is not tested
Metrics: KPIs and KRIs
- KPI
- how well a process performs
- KRI
- early warning risk is rising
- MTTD
- mean time to detect
- MTTR
- mean time to respond or remediate
- Dwell time
- attacker present before detection
- Vulnerability aging
- how long findings stay open
- Patch compliance
- share of assets current
- False positive rate
- alerts that wasted analyst time
Compliance metrics measure activity; effectiveness metrics measure outcomes. The exam wants you to know the difference
Evidence and reporting
- System-generated evidence beats testimony
- Interview, observe, inspect, re-perform
- Sampling must be representative
- Findings: condition, cause, impact, recommendation
- Rate severity, assign owner, set date
- Executive summary for management, detail for engineers
- Track exceptions and risk acceptance
- Management review closes the loop
Reviews the exam expects
- User access review and recertification
- Privileged account review
- Separation of duties review
- Backup verification by real restore
- Awareness testing with phishing simulations
- Configuration compliance against baselines
- Key and certificate management review
- Disaster recovery and BCP exercises
- Account management: joiners, movers, leavers
Rapid recall: acronyms
- CVE
- named public vulnerability
- CWE
- weakness category, root cause type
- CVSS
- severity score 0 to 10
- CPE
- platform naming for assets
- SCAP
- automation protocols, OVAL, XCCDF
- NVD
- US vulnerability database
- STIX, TAXII
- threat intel format and transport
- ATT&CK
- adversary tactics and techniques
- PTES, OSSTMM
- penetration testing methodologies
Know the ladder
- Scan finds
- Test proves
- Exercise rehearses
- Audit attests
- Scanner cannot prove exploitability
- Pen test proves a path exists
- Red team proves detection gaps
- Audit proves controls to outsiders
- Each rung costs more, assures more
Reference strip: standards, reports, findings
Standards
- NIST SP 800-115 technical testing
- NIST SP 800-53A assessing controls
- ISO 27001 and 27002
- SSAE 18, ISAE 3402 attestation
- PCI DSS quarterly ASV scans
Report types
- SOC 1, SOC 2, SOC 3
- Type I design, Type II operation
- Pen test report with proof of concept
- Vulnerability scan with CVSS ranking
- Audit report with management response
Testing methods
- SAST, DAST, IAST, RASP, SCA
- Fuzzing, symbolic execution
- Misuse case, interface, regression
- Code review: pair, tool-assisted, Fagan
Teams and boxes
- Red, blue, purple, white
- Black, gray, white box
- Blind and double blind
- Bug bounty as continuous testing
Common web findings
- Injection, XXE, insecure deserialization
- JWT accepting the none algorithm
- Missing HSTS and security headers
- Username enumeration by timing
- Rate limits per session, not per IP
Quick exam traps
- Trap: A clean vulnerability scan proves the system is secure
- Trap: SOC 2 Type I covers operating effectiveness over time
- Trap: Testers should exploit every finding to show impact
- Trap: Penetration testers set their own scope
- Trap: A tabletop exercise proves the recovery site works
- Trap: SAST finds runtime misconfiguration
- Trap: 100 percent patch compliance means the program is effective
- Trap: Uncredentialed scans see what credentialed scans see
cybercertprep.com · original revision sheet written from the public body of knowledge