6.0 Security Assessment and Testing

Security Testing Practice Questions

Vulnerability assessment vs. penetration testing, testing phases, SAST/DAST/IAST, fuzzing, and test coverage.

One solved question, so you can see how these are marked

A security manager needs a recurring view of weaknesses across 4,000 endpoints and wants to prioritize remediation without attempting to gain unauthorized access. Which activity BEST fits the need?

A vulnerability assessment that identifies and rates weaknesses

A vulnerability assessment systematically identifies and prioritizes weaknesses, while a penetration test attempts exploitation. Red teaming is an adversary simulation, and misuse case review focuses on abusive application behavior rather than broad endpoint exposure.

Every question in the set below is marked like this. The answers stay hidden until you pick one.