nerdexam
(ISC)2

CISSP · Question #1147

An establish information technology (IT) consulting firm is considering acquiring a successful local startup. To gain a comprehensive understanding of the startup's security posture' which type of…

The correct answer is B. A penetration test. When an acquiring firm wants a comprehensive understanding of a target's actual security posture, a penetration test provides the most realistic, evidence-based assessment by actively probing defenses and uncovering exploitable vulnerabilities.

Submitted by zhang_li· Mar 5, 2026Security Assessment and Testing

Question

An establish information technology (IT) consulting firm is considering acquiring a successful local startup. To gain a comprehensive understanding of the startup's security posture' which type of assessment provides the BEST information?

Options

  • AA security audit
  • BA penetration test
  • CA tabletop exercise
  • DA security threat model

How the community answered

(26 responses)
  • A
    27% (7)
  • B
    58% (15)
  • C
    12% (3)
  • D
    4% (1)

Why each option

When an acquiring firm wants a comprehensive understanding of a target's actual security posture, a penetration test provides the most realistic, evidence-based assessment by actively probing defenses and uncovering exploitable vulnerabilities.

AA security audit

A security audit evaluates compliance against a defined standard or policy framework, but does not actively test whether controls are effective or exploitable, making it less comprehensive for understanding actual security posture.

BA penetration testCorrect

A penetration test actively simulates real-world attacks against the startup's systems, networks, and applications, producing concrete evidence of exploitable vulnerabilities and their potential business impact. This hands-on technical assessment reveals the true security posture-including misconfigurations, unpatched systems, and weak controls-that other assessment types may miss. For an acquisition scenario, this gives the acquiring firm objective, technical data to inform risk decisions and valuation.

CA tabletop exercise

A tabletop exercise is a discussion-based simulation of incident response scenarios that tests people and processes, not technical controls or actual vulnerabilities in systems.

DA security threat model

A security threat model is a design-phase analysis that identifies potential threats against an architecture, but it does not validate whether those threats are currently exploitable or how well existing controls mitigate them.

Concept tested: Selecting appropriate security assessment type for acquisition due diligence

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#security assessment#penetration testing#due diligence#M&A security

Community Discussion

No community discussion yet for this question.

Full CISSP Practice