Back to Domains
🔍Domain 6

Security Assessment and Testing

12%Exam Weight
5Subdomains
6.1

Design and validate assessment, test, and audit strategies

Key Concepts

InternalExternalThird-partyLocation based testing
6.2

Conduct security control testing

Key Concepts

Vulnerability assessmentPenetration testingRed teamBlue teamPurple teamLog reviewsSynthetic transactionsCode reviewMisuse case testingCoverage analysisInterface testingBreach attack simulationsCompliance checks
6.3

Collect security process data

Key Concepts

Account managementManagement reviewKPIsRisk indicatorsBackup verificationTrainingDRBC
6.4

Analyze test output and generate report

Key Concepts

RemediationException handlingEthical disclosure
6.5

Conduct or facilitate security audits

Key Concepts

Internal auditsExternal auditsThird-party auditsLocation based audits