Exam objective
SY0-701 5.5: Audits and Assessments
Audits and Assessments for Security+
This Security+ topic covers attestation as a formal assertion or assurance output connected to assessment results; Internal assessment contexts: compliance, audit committee, and self-assessments; External assessment contexts: regulatory, examinations, assessment, and independent third-party audit; Penetration testing types and purposes: physical, offensive, defensive, integrated, known environment, partially known environment, unknown environment, reconnaissance, passive reconnaissance, and active reconnaissance.
Start first lesson3 lessons in this topic
Common mistakes to avoid
Learners often assume self-assessment is the same as an independent audit. The correction: self-assessment is performed by the responsible team; independent assurance requires separation from the control owner.
Learners often confuse external assessment with third-party risk assessment. The correction: external assessment describes who performs or requires the review; third-party risk is the vendor management process that may use the review as evidence.
Learners often confuse known environment with active reconnaissance. The correction: known/partially known/unknown describes how much information testers start with; active/passive describes how reconnaissance is performed.