CISSP · Free practice question 8 of 12
Breach and attack simulation platforms
Carrick Insurance wants to check continuously, rather than once a year, that its email filtering, endpoint and network controls still block common attack techniques after every configuration change. Which solution BEST meets this need?
- A.A quarterly questionnaire completed by each control owner
- B.A breach and attack simulation platform running automated attack scenarios
- C.An annual third-party audit of the information security policies
- D.A larger SIEM license so that more log sources can be collected
Show answer and explanation
Correct answer: B. A breach and attack simulation platform running automated attack scenarios
Why: Breach and attack simulation tools run automated, safe simulations of real attack techniques on a schedule and report which controls blocked or detected them, providing continuous validation as the environment changes. Policy audits and self-assessment questionnaires check documentation and opinions rather than real control behavior, and collecting more logs does not by itself test whether controls work.
More free CISSP questions
- Senior management ultimate security accountability
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Known-plaintext cryptanalytic attack
- Air-gapped network physical segmentation
- Role-based access control by job function
- Misuse case testing of abuse scenarios
- Proactive hypothesis-driven threat hunting
- Lessons learned after incident closure
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time