nerdexam
(ISC)2

CISSP · Question #1179

Which of the following is a common term for log reviews, synthetic transactions, and code reviews?

The correct answer is A. Security control testing. Log reviews, synthetic transactions, and code reviews are all examples of security control testing techniques used to evaluate the effectiveness of security controls.

Submitted by khalil_dz· Mar 5, 2026Security Assessment and Testing

Question

Which of the following is a common term for log reviews, synthetic transactions, and code reviews?

Options

  • ASecurity control testing
  • BApplication development
  • CSpiral development functional testing
  • DDevOps Integrated Product Team (IPT) development

How the community answered

(27 responses)
  • A
    89% (24)
  • B
    7% (2)
  • D
    4% (1)

Why each option

Log reviews, synthetic transactions, and code reviews are all examples of security control testing techniques used to evaluate the effectiveness of security controls.

ASecurity control testingCorrect

Security control testing encompasses a variety of assessment techniques - including log reviews (examining audit trails for anomalies), synthetic transactions (simulating user activity to test system behavior), and code reviews (analyzing source code for vulnerabilities) - all of which are used to verify that security controls are functioning as intended. These methods are formally categorized under security control testing in frameworks like NIST SP 800-53A and ISC2 security assessment guidance.

BApplication development

Application development is a software engineering lifecycle process focused on building applications, not a term that categorizes security assessment techniques like log reviews or synthetic transactions.

CSpiral development functional testing

Spiral development functional testing refers to a specific iterative software development methodology's testing phase, not a common umbrella term for security assessment techniques.

DDevOps Integrated Product Team (IPT) development

DevOps Integrated Product Team (IPT) development is a project management and collaboration framework used in defense and enterprise environments, and does not describe the category of security evaluation techniques listed.

Concept tested: Security control testing techniques and categorization

Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final

Topics

#security control testing#log review#code review#synthetic transactions

Community Discussion

No community discussion yet for this question.

Full CISSP Practice