CISSP Practice Question (Domain 6: Security Assessment and Testing)
A company uses red team exercises to validate detection and response capabilities. After several successful simulations, leadership concludes incident readiness is high. An independent review finds that scenarios are reused and defenders have begun anticipating tactics. Management wants realistic assurance without increasing test frequency.
What is the MOST appropriate change to make?
A. Rotate red team members to reduce defender familiarity
B. Introduce threat informed testing with adaptive scenario design
C. Increase reliance on automated attack simulation tools
D. Separate detection and response teams during exercises
Come back for the answer tomorrow, or study more now!
2
18 comments
Vincent Primiani
7
CISSP Practice Question (Domain 6: Security Assessment and Testing)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by