6.0 Security Assessment and Testing
Audits, Logging & Metrics Practice Questions
Audit types, SOC 1/2/3 and Type I vs. Type II, log review and SIEM, account reviews, and KPIs vs. KRIs.
One solved question, so you can see how these are marked
A security manager wants an unbiased evaluation of controls operated by the company itself, with the results used to improve the security program before the next certification review. Which assessment is BEST?
An internal audit performed under an approved audit plan
An internal audit evaluates the organization's own controls and can support improvement under an approved audit plan. A customer-commissioned or independent external audit provides outside assurance, while a penetration test targets technical weaknesses rather than the full control program.
Every question in the set below is marked like this. The answers stay hidden until you pick one.