5.5 Explain types and purposes of audits and assessments
Domain 5: Security Program Management and Oversight
This objective sorts audits and assessments by who performs them and why. Internal activities include compliance checks, audit committee oversight, and self-assessments; external activities include regulatory examinations, independent third-party audits, and formal attestation by an auditor. Then comes penetration testing, which the exam breaks down along several axes: physical versus offensive versus defensive versus integrated testing; known, partially known, and unknown environments (the successors to white, gray, and black box); and reconnaissance that is passive or active. Rules of engagement define scope, timing, and permitted techniques before any test starts. Distinguish a vulnerability scan from a penetration test — the scan identifies weaknesses automatically, the pen test actively exploits them to demonstrate impact. Candidates most often miss the environment-knowledge terminology because they studied older box-color labels, and they confuse attestation (a formal statement that controls meet a standard) with the audit itself. Also be ready to say why independence matters: external audits carry weight precisely because the assessor has no stake in the result.
What you must know
- internal vs external audits
- attestation
- penetration test types
- known vs unknown environment
- passive vs active reconnaissance
- rules of engagement
common pitfall · Candidates rely on outdated white/gray/black box labels and stumble on the known, partially known, and unknown environment terminology the current exam uses.
Is objective 5.5 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free