StudyToCert

All certifications / CISA / Lessons

ISACA Certified Information Systems Auditor (CISA) 2024 job practice · Domain 5: Protection of information assets

Security testing tools and techniques: vulnerability scanning, penetration testing and configuration review

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Security testing finds weaknesses before attackers do and gives evidence about whether controls actually work. An auditor may perform some tests directly, rely on tests performed by others such as an internal security team or an external firm, or review the organization's own testing program. In every case, the questions are whether testing is risk-based, performed by qualified and suitably independent people, properly authorized, and followed by timely remediation.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISA study plan