ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 5.5 — Distinguish audits, reviews, and security assessments

Choose an engagement by the assurance question. An audit evaluates evidence against defined criteria. An assessment examines control design or effectiveness. An examination may be performed under a regulatory authority. An attestation is a formal assertion or report about a subject. A penetration test safely attempts to demonstrate exploitable paths within authorization.

Internal reviews use organizational staff or governance functions and can include self-assessments, compliance reviews, and audit-committee oversight. They support frequent improvement but may have independence limits. External work can include regulatory examinations, independent assessments, and third-party audits. Independence, competence, scope, and evidence determine confidence—not simply “external.”

Penetration-test choices

Physical testing evaluates facilities and entry controls. Offensive teams emulate attack techniques. Defensive teams detect and respond. Integrated or collaborative exercises test both sides and coordination.

A known-environment test provides extensive internal knowledge; a partially known test supplies some context; an unknown-environment test begins with little information. These terms describe tester knowledge, not permission. Every test needs explicit authorization and rules of engagement.

Passive reconnaissance observes available information without direct interaction where practical. Active reconnaissance queries or interacts with targets and carries more detection and operational risk. The testing plan should define targets, exclusions, dates, contacts, allowed techniques, stopping conditions, evidence handling, and reporting.

Findings require confirmation, impact, recommendation, owner, due date, and retest where appropriate. An audit exception and a vulnerability finding can describe the same technical condition but answer different questions: one is nonconformance to criteria, the other is exploitable weakness.

Decision rule: identify the assurance objective, required independence, criteria, permitted evidence, and acceptable operational risk before selecting the engagement.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free