CompTIA Security+ SY0-701 Audits and Assessments Practice Test

 

Topic 27 focuses on Audits and Assessments for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which audit is performed by or for the organization to evaluate adherence to its own and external requirements?

  1. Internal compliance audit
  2. Defensive assessment
  3. Self-assessment
  4. Integrated assessment

Correct Answer: A

 

Correct Answer

Answer A is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

Answer B is incorrect because Defensive assessment would fit a different scenario. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer C is incorrect because Self-assessment addresses a different requirement. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

Answer D is incorrect because Integrated assessment represents a different security function. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

 

Question 2

To provide independent oversight of audit findings and remediation, which security approach should be selected?

  1. Audit committee
  2. Partially known environment test
  3. Offensive penetration test
  4. Self-assessment

Correct Answer: A

 

Correct Answer

Answer A is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

Answer B is incorrect because Partially known environment test addresses a different security requirement. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer C is incorrect because Offensive penetration test would fit a different scenario. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

Answer D is incorrect because Self-assessment addresses a different requirement. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

 

Question 3

Which evaluation is performed by the team or organization responsible for the controls?

  1. Defensive assessment
  2. Integrated assessment
  3. Regulatory examination
  4. Self-assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Self-assessment means an evaluation performed by the team or organization responsible for the controls.

Incorrect Answers

Answer A is incorrect because Defensive assessment would fit a different scenario. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer B is incorrect because Integrated assessment addresses a different requirement. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer C is incorrect because Regulatory examination represents a different security function. Regulatory examination refers to formal review performed under the authority of a regulator.

 

Question 4

To determine whether the organization meets binding regulatory expectations, which security approach should be selected?

  1. Regulatory examination
  2. Audit committee
  3. Independent third-party audit
  4. Internal compliance audit

Correct Answer: A

 

Correct Answer

Answer A is correct because Regulatory examination means formal review performed under the authority of a regulator.

Incorrect Answers

Answer B is incorrect because Audit committee addresses a different requirement. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Answer C is incorrect because Independent third-party audit addresses a different security requirement. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

Answer D is incorrect because Internal compliance audit would fit a different scenario. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

 

Question 5

Which term describes assessment performed by an external party that is not responsible for operating the controls being reviewed?

  1. Physical penetration test
  2. Independent third-party audit
  3. Integrated assessment
  4. Self-assessment

Correct Answer: B

 

Correct Answer

Answer B is correct because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed.

Incorrect Answers

Answer A is incorrect because Physical penetration test addresses a different requirement. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Answer C is incorrect because Integrated assessment represents a different security function. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer D is incorrect because Self-assessment would fit a different scenario. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

 

Question 6

To test whether an attacker could gain unauthorized physical access, which security approach should be selected?

  1. Self-assessment
  2. Integrated assessment
  3. Unknown-environment test
  4. Physical penetration test

Correct Answer: D

 

Correct Answer

Answer D is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Incorrect Answers

Answer A is incorrect because Self-assessment addresses a different requirement. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

Answer B is incorrect because Integrated assessment addresses a different security requirement. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer C is incorrect because Unknown-environment test would fit a different scenario. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

 

Question 7

Which term describes security test focused on emulating attacker techniques to find and exploit weaknesses?

  1. Known-environment test
  2. Offensive penetration test
  3. Physical penetration test
  4. Defensive assessment

Correct Answer: B

 

Correct Answer

Answer B is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses.

Incorrect Answers

Answer A is incorrect because Known-environment test addresses a different requirement. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

Answer C is incorrect because Physical penetration test would fit a different scenario. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Answer D is incorrect because Defensive assessment represents a different security function. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

 

Question 8

To measure how well defenders identify and handle malicious activity, which security approach should be selected?

  1. Active reconnaissance
  2. Known-environment test
  3. Independent third-party audit
  4. Defensive assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Incorrect Answers

Answer A is incorrect because Active reconnaissance addresses a different security requirement. Active reconnaissance refers to information gathering that directly interacts with target systems or networks.

Answer B is incorrect because Known-environment test addresses a different requirement. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

Answer C is incorrect because Independent third-party audit would fit a different scenario. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

 

Question 9

Which term describes exercise combining offensive and defensive elements to evaluate end-to-end security capability?

  1. Integrated assessment
  2. Offensive penetration test
  3. Passive reconnaissance
  4. Physical penetration test

Correct Answer: A

 

Correct Answer

Answer A is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Incorrect Answers

Answer B is incorrect because Offensive penetration test represents a different security function. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

Answer C is incorrect because Passive reconnaissance would fit a different scenario. Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected.

Answer D is incorrect because Physical penetration test addresses a different requirement. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

 

Question 10

To perform deep testing efficiently with broad internal knowledge, which security approach should be selected?

  1. Self-assessment
  2. Known-environment test
  3. Unknown-environment test
  4. Offensive penetration test

Correct Answer: B

 

Correct Answer

Answer B is correct because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials.

Incorrect Answers

Answer A is incorrect because Self-assessment would fit a different scenario. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

Answer C is incorrect because Unknown-environment test addresses a different security requirement. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

Answer D is incorrect because Offensive penetration test addresses a different requirement. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

 

Question 11

Which term describes assessment in which testers receive limited knowledge similar to a user or partner perspective?

  1. Offensive penetration test
  2. Partially known environment test
  3. Known-environment test
  4. Audit committee

Correct Answer: B

 

Correct Answer

Answer B is correct because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective.

Incorrect Answers

Answer A is incorrect because Offensive penetration test represents a different security function. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

Answer C is incorrect because Known-environment test addresses a different requirement. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

Answer D is incorrect because Audit committee would fit a different scenario. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

 

Question 12

To simulate an external attacker who must discover the environment, which security approach should be selected?

  1. Audit committee
  2. Integrated assessment
  3. Unknown-environment test
  4. Offensive penetration test

Correct Answer: C

 

Correct Answer

Answer C is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge.

Incorrect Answers

Answer A is incorrect because Audit committee addresses a different security requirement. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Answer B is incorrect because Integrated assessment would fit a different scenario. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer D is incorrect because Offensive penetration test addresses a different requirement. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

 

Question 13

Which term describes information gathering performed without directly interacting with the target systems in a way likely to be detected?

  1. Defensive assessment
  2. Passive reconnaissance
  3. Unknown-environment test
  4. Audit committee

Correct Answer: B

 

Correct Answer

Answer B is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected.

Incorrect Answers

Answer A is incorrect because Defensive assessment addresses a different requirement. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer C is incorrect because Unknown-environment test represents a different security function. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

Answer D is incorrect because Audit committee would fit a different scenario. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

 

Question 14

To discover live services and technical details with greater detection risk, which security approach should be selected?

  1. Active reconnaissance
  2. Partially known environment test
  3. Regulatory examination
  4. Unknown-environment test

Correct Answer: A

 

Correct Answer

Answer A is correct because Active reconnaissance means information gathering that directly interacts with target systems or networks.

Incorrect Answers

Answer B is incorrect because Partially known environment test would fit a different scenario. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer C is incorrect because Regulatory examination addresses a different security requirement. Regulatory examination refers to formal review performed under the authority of a regulator.

Answer D is incorrect because Unknown-environment test addresses a different requirement. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

 

Question 15

To identify control gaps before or independent of an external examination, which security approach should be selected?

  1. Independent third-party audit
  2. Internal compliance audit
  3. Physical penetration test
  4. Known-environment test

Correct Answer: B

 

Correct Answer

Answer B is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

Answer A is incorrect because Independent third-party audit would fit a different scenario. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

Answer C is incorrect because Physical penetration test addresses a different security requirement. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Answer D is incorrect because Known-environment test represents a different security function. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

 

Question 16

Which governance body oversees audit, financial reporting, controls, or related assurance activities?

  1. Independent third-party audit
  2. Self-assessment
  3. Internal compliance audit
  4. Audit committee

Correct Answer: D

 

Correct Answer

Answer D is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

Answer A is incorrect because Independent third-party audit addresses a different requirement. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

Answer B is incorrect because Self-assessment represents a different security function. Self-assessment refers to an evaluation performed by the team or organization responsible for the controls.

Answer C is incorrect because Internal compliance audit addresses a different security requirement. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

 

Question 17

To identify readiness and gaps using internal knowledge at relatively low cost, which security approach should be selected?

  1. Self-assessment
  2. Active reconnaissance
  3. Physical penetration test
  4. Independent third-party audit

Correct Answer: A

 

Correct Answer

Answer A is correct because Self-assessment means an evaluation performed by the team or organization responsible for the controls.

Incorrect Answers

Answer B is incorrect because Active reconnaissance would fit a different scenario. Active reconnaissance refers to information gathering that directly interacts with target systems or networks.

Answer C is incorrect because Physical penetration test addresses a different security requirement. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Answer D is incorrect because Independent third-party audit represents a different security function. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

 

Question 18

Which term describes formal review performed under the authority of a regulator?

  1. Audit committee
  2. Regulatory examination
  3. Known-environment test
  4. Integrated assessment

Correct Answer: B

 

Correct Answer

Answer B is correct because Regulatory examination means formal review performed under the authority of a regulator.

Incorrect Answers

Answer A is incorrect because Audit committee addresses a different requirement. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Answer C is incorrect because Known-environment test addresses a different security requirement. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

Answer D is incorrect because Integrated assessment represents a different security function. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

 

Question 19

To provide stronger independent assurance to stakeholders, which security approach should be selected?

  1. Independent third-party audit
  2. Audit committee
  3. Integrated assessment
  4. Physical penetration test

Correct Answer: A

 

Correct Answer

Answer A is correct because Independent third-party audit means assessment performed by an external party that is not responsible for operating the controls being reviewed.

Incorrect Answers

Answer B is incorrect because Audit committee represents a different security function. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Answer C is incorrect because Integrated assessment would fit a different scenario. Integrated assessment refers to exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Answer D is incorrect because Physical penetration test addresses a different security requirement. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

 

Question 20

Which term describes authorized attempt to bypass physical controls such as locks, badges, or facility procedures?

  1. Internal compliance audit
  2. Partially known environment test
  3. Physical penetration test
  4. Unknown-environment test

Correct Answer: C

 

Correct Answer

Answer C is correct because Physical penetration test means authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Incorrect Answers

Answer A is incorrect because Internal compliance audit addresses a different security requirement. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Answer B is incorrect because Partially known environment test represents a different security function. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer D is incorrect because Unknown-environment test addresses a different requirement. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

 

Question 21

To demonstrate exploitable attack paths and impact, which security approach should be selected?

  1. Defensive assessment
  2. Partially known environment test
  3. Independent third-party audit
  4. Offensive penetration test

Correct Answer: D

 

Correct Answer

Answer D is correct because Offensive penetration test means security test focused on emulating attacker techniques to find and exploit weaknesses.

Incorrect Answers

Answer A is incorrect because Defensive assessment represents a different security function. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer B is incorrect because Partially known environment test addresses a different security requirement. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer C is incorrect because Independent third-party audit would fit a different scenario. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

 

Question 22

Which term describes exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness?

  1. Partially known environment test
  2. Active reconnaissance
  3. Defensive assessment
  4. Passive reconnaissance

Correct Answer: C

 

Correct Answer

Answer C is correct because Defensive assessment means exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Incorrect Answers

Answer A is incorrect because Partially known environment test addresses a different security requirement. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer B is incorrect because Active reconnaissance represents a different security function. Active reconnaissance refers to information gathering that directly interacts with target systems or networks.

Answer D is incorrect because Passive reconnaissance addresses a different requirement. Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected.

 

Question 23

To test both attack paths and the organization’s ability to detect and respond, which security approach should be selected?

  1. Internal compliance audit
  2. Defensive assessment
  3. Audit committee
  4. Integrated assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Integrated assessment means exercise combining offensive and defensive elements to evaluate end-to-end security capability.

Incorrect Answers

Answer A is incorrect because Internal compliance audit addresses a different security requirement. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Answer B is incorrect because Defensive assessment would fit a different scenario. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer C is incorrect because Audit committee represents a different security function. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

 

Question 24

Which term describes assessment in which testers receive extensive information about systems, architecture, or credentials?

  1. Independent third-party audit
  2. Active reconnaissance
  3. Defensive assessment
  4. Known-environment test

Correct Answer: D

 

Correct Answer

Answer D is correct because Known-environment test means assessment in which testers receive extensive information about systems, architecture, or credentials.

Incorrect Answers

Answer A is incorrect because Independent third-party audit addresses a different requirement. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

Answer B is incorrect because Active reconnaissance represents a different security function. Active reconnaissance refers to information gathering that directly interacts with target systems or networks.

Answer C is incorrect because Defensive assessment addresses a different security requirement. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

 

Question 25

To balance realism and efficiency with some contextual information, which security approach should be selected?

  1. Physical penetration test
  2. Offensive penetration test
  3. Partially known environment test
  4. Audit committee

Correct Answer: C

 

Correct Answer

Answer C is correct because Partially known environment test means assessment in which testers receive limited knowledge similar to a user or partner perspective.

Incorrect Answers

Answer A is incorrect because Physical penetration test represents a different security function. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

Answer B is incorrect because Offensive penetration test addresses a different security requirement. Offensive penetration test refers to security test focused on emulating attacker techniques to find and exploit weaknesses.

Answer D is incorrect because Audit committee would fit a different scenario. Audit committee refers to a governance body that oversees audit, financial reporting, controls, or related assurance activities.

 

Question 26

Which term describes assessment in which testers begin with little or no internal knowledge?

  1. Internal compliance audit
  2. Unknown-environment test
  3. Defensive assessment
  4. Known-environment test

Correct Answer: B

 

Correct Answer

Answer B is correct because Unknown-environment test means assessment in which testers begin with little or no internal knowledge.

Incorrect Answers

Answer A is incorrect because Internal compliance audit addresses a different security requirement. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Answer C is incorrect because Defensive assessment addresses a different requirement. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer D is incorrect because Known-environment test represents a different security function. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

 

Question 27

To collect public or third-party information while minimizing direct contact, which security approach should be selected?

  1. Defensive assessment
  2. Internal compliance audit
  3. Passive reconnaissance
  4. Independent third-party audit

Correct Answer: C

 

Correct Answer

Answer C is correct because Passive reconnaissance means information gathering performed without directly interacting with the target systems in a way likely to be detected.

Incorrect Answers

Answer A is incorrect because Defensive assessment would fit a different scenario. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer B is incorrect because Internal compliance audit represents a different security function. Internal compliance audit refers to an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Answer D is incorrect because Independent third-party audit addresses a different security requirement. Independent third-party audit refers to assessment performed by an external party that is not responsible for operating the controls being reviewed.

 

Question 28

Which term describes information gathering that directly interacts with target systems or networks?

  1. Active reconnaissance
  2. Partially known environment test
  3. Regulatory examination
  4. Passive reconnaissance

Correct Answer: A

 

Correct Answer

Answer A is correct because Active reconnaissance means information gathering that directly interacts with target systems or networks.

Incorrect Answers

Answer B is incorrect because Partially known environment test represents a different security function. Partially known environment test refers to assessment in which testers receive limited knowledge similar to a user or partner perspective.

Answer C is incorrect because Regulatory examination addresses a different security requirement. Regulatory examination refers to formal review performed under the authority of a regulator.

Answer D is incorrect because Passive reconnaissance addresses a different requirement. Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected.

 

Question 29

An organization commissions an assessment of its compliance with its own policies and applicable external requirements. The assessment is performed by or for the organization itself. Which audit type is this?

  1. Passive reconnaissance
  2. Unknown-environment test
  3. Internal compliance audit
  4. Regulatory examination

Correct Answer: C

 

Correct Answer

Answer C is correct because Internal compliance audit means an audit performed by or for the organization to evaluate adherence to its own and external requirements.

Incorrect Answers

Answer A is incorrect because Passive reconnaissance addresses a different security requirement. Passive reconnaissance refers to information gathering performed without directly interacting with the target systems in a way likely to be detected.

Answer B is incorrect because Unknown-environment test would fit a different scenario. Unknown-environment test refers to assessment in which testers begin with little or no internal knowledge.

Answer D is incorrect because Regulatory examination addresses a different requirement. Regulatory examination refers to formal review performed under the authority of a regulator.

 

Question 30

Senior governance members need independent oversight of audit findings and the progress of corrective actions. Which body is responsible for this oversight?

  1. Known-environment test
  2. Defensive assessment
  3. Audit committee
  4. Physical penetration test

Correct Answer: C

 

Correct Answer

Answer C is correct because Audit committee means a governance body that oversees audit, financial reporting, controls, or related assurance activities.

Incorrect Answers

Answer A is incorrect because Known-environment test represents a different security function. Known-environment test refers to assessment in which testers receive extensive information about systems, architecture, or credentials.

Answer B is incorrect because Defensive assessment addresses a different requirement. Defensive assessment refers to exercise focused on evaluating detection, response, hardening, or defensive-control effectiveness.

Answer D is incorrect because Physical penetration test would fit a different scenario. Physical penetration test refers to authorized attempt to bypass physical controls such as locks, badges, or facility procedures.

img