100% Free Exams (No login or credit card required)

Section 5.5

Demonstrate your acquired knowledge about the types and purposes of audits and
assessments. This will demonstrate your proficiency for section 5.5 of the Security+ SY0-701 objectives.

1 / 25

Which test scenario simulates a full attack path with no insider access?

2 / 25

An audit of encryption standards would fall under which category?

3 / 25

Which best describes the purpose of an internal audit committee?

4 / 25

A company brings in an outside firm to validate its security posture. This is a:

5 / 25

Which test would best validate a physical access control system?

6 / 25

In penetration testing, what is the purpose of active reconnaissance?

7 / 25

An audit conducted to preempt a regulatory inspection is called a:

8 / 25

Why are self-assessments sometimes limited in objectivity?

9 / 25

Which penetration testing approach uses open-source research only?

10 / 25

A red team primarily simulates:

11 / 25

What is the main value of a regulatory audit?

12 / 25

A partially known environment test involves:

13 / 25

Which test is used to identify exploitable vulnerabilities by simulation?

14 / 25

An attestation form is most commonly used to:

15 / 25

Which penetration test focuses only on response and defense?

16 / 25

What makes an external examination distinct?

17 / 25

Which penetration test type combines both red and blue teams?

18 / 25

Which activity comes first in most penetration tests?

19 / 25

Which audit type is most likely triggered by government agencies?

20 / 25

Which testing method mimics an outside attacker with no prior knowledge?

21 / 25

An audit committee is typically responsible for:

22 / 25

What is a key trait of a third-party audit?

23 / 25

A company performs its own security review. What is this called?

24 / 25

Which best defines attestation in a compliance context?

25 / 25

What is the primary goal of an internal compliance audit?

Your score is

The average score is 0%

0%