CertKeen

CISSP · Free practice question 8 of 12

Breach and attack simulation platforms

Carrick Insurance wants to check continuously, rather than once a year, that its email filtering, endpoint and network controls still block common attack techniques after every configuration change. Which solution BEST meets this need?

  1. A.A quarterly questionnaire completed by each control owner
  2. B.A breach and attack simulation platform running automated attack scenarios
  3. C.An annual third-party audit of the information security policies
  4. D.A larger SIEM license so that more log sources can be collected
Show answer and explanation

Correct answer: B. A breach and attack simulation platform running automated attack scenarios

Why: Breach and attack simulation tools run automated, safe simulations of real attack techniques on a schedule and report which controls blocked or detected them, providing continuous validation as the environment changes. Policy audits and self-assessment questionnaires check documentation and opinions rather than real control behavior, and collecting more logs does not by itself test whether controls work.

More free CISSP questions