CISSP Mastery · Module 6 / 8
Domain 6: Security Assessment & Testing
Trust, but verify: Mastering vulnerability management, audits, and security assessments.
Your progress
Domain 6 of 8 75%
12%
Exam weight
CVSS
Prioritize
6 / 8
Domain focus
PDCA
Continuous test
Open preview · Domain overview
Why Domain 6 is where policy meets evidence
Assessments produce signal; audits produce attestation; penetration tests simulate adversaries. Domain 6 trains you to pick the right instrument, run a defensible vulnerability lifecycle, and translate technical risk into decisions executives can fund.
Domain 6 is where assurance becomes evidence: assessments widen visibility, audits prove control design and operation, and penetration tests stress realism. Pair it with Domain 5 (who gets access) and Domain 7 (how incidents are run) for a complete operational story.
-
Three different lenses
Assessment = breadth and posture. Audit = criteria and evidence. Pen test = depth and exploitation under rules of engagement.
-
Vulnerability management is a loop
Identify, analyze, prioritize, remediate, verify — skip verification and you only moved the risk to next quarter.
-
Testing depth is a dial
Black, gray, and white-box trade attacker realism for source visibility — the exam loves scenario fit, not buzzwords.
-
Reporting closes the sale
A perfect finding without a business narrative does not get patched. Learn the executive storyline: impact, likelihood, cost of delay.
Quick check
Domain 6 quiz
One question at a time — instant feedback. Pair it with the diagrams and Pro-Tip callouts above.
Quiz progress
Question 1 of 5
1.SOC 2 Type I differs from SOC 2 Type II mainly because Type II:
Exam Pro-Tip
Pro-Tip: Type I is point-in-time design; Type II includes operating effectiveness over time.
2.SOC 1 reports are primarily relevant to controls impacting:
Exam Pro-Tip
Pro-Tip: SOC 1 focuses on ICFR-related controls; SOC 2 addresses trust service criteria.
3.A strong management review for the security program should include:
Exam Pro-Tip
Pro-Tip: Governance decisions require evidence across risk, assurance, and performance.
4.Which KPI best indicates vulnerability remediation effectiveness?
Exam Pro-Tip
Pro-Tip: Remediation speed against SLA is a practical control health indicator.
5.CVSS base score should be treated as:
Exam Pro-Tip
Pro-Tip: Effective prioritization combines severity, exposure, exploitability, and asset criticality.
Your score: 0 / 5
Ready for Domain 7?
Module 6 frames assessment, testing, and vulnerability management as one continuous loop — not a checkbox exercise. Proceed to Domain 7 when you are ready. All eight domain guides remain free; save the Final Mock Exam for your capstone run.