StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 6: Security assessment & testing

Log reviews, synthetic transactions and breach and attack simulation

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Testing is not only about hiring testers once a year. Much of your assurance comes from continuously examining what systems already tell you and from exercising them in controlled ways. This topic covers three techniques: reviewing logs, running synthetic transactions and using breach and attack simulation (BAS). Together they give ongoing evidence that controls still work between formal assessments.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan