nerdexam
(ISC)2

CISSP · Question #96

What is the FIRST step in developing a security test and its evaluation?

The correct answer is C. Identify all applicable security requirements. Developing a security test begins with identifying all applicable security requirements, as you cannot design or evaluate a test without first knowing what standards and controls must be met.

Submitted by kwame.gh· Mar 5, 2026Security Assessment and Testing

Question

What is the FIRST step in developing a security test and its evaluation?

Options

  • ADetermine testing methods
  • BDevelop testing procedures
  • CIdentify all applicable security requirements
  • DIdentify people, processes, and products not in compliance

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    14% (6)
  • C
    74% (32)
  • D
    5% (2)

Why each option

Developing a security test begins with identifying all applicable security requirements, as you cannot design or evaluate a test without first knowing what standards and controls must be met.

ADetermine testing methods

Determining testing methods comes after requirements are identified, since the chosen methods must align with and be driven by the specific security requirements that apply.

BDevelop testing procedures

Developing testing procedures is a later step that translates requirements and selected methods into actionable steps, and cannot be done meaningfully before requirements are established.

CIdentify all applicable security requirementsCorrect

Identifying all applicable security requirements is the foundational first step because it establishes the scope and baseline criteria against which all testing will be measured. Without knowing which regulatory, organizational, or technical security requirements apply, there is no basis for determining what to test, how to test it, or what constitutes a pass or fail. All subsequent steps - such as selecting methods and developing procedures - depend on this requirements baseline.

DIdentify people, processes, and products not in compliance

Identifying people, processes, and products not in compliance is an outcome or result of executing the security test, not a step in initially developing the test itself.

Concept tested: Security test development lifecycle and planning sequence

Source: https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final

Topics

#security testing methodology#test planning#security requirements#assessment scope

Community Discussion

No community discussion yet for this question.

Full CISSP Practice