StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 6: Security assessment & testing

Vulnerability assessment and penetration testing (rules of engagement, testing knowledge levels)

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Vulnerability assessment and penetration testing are related but different. A vulnerability assessment identifies, quantifies and prioritizes weaknesses, usually with automated scanners that compare systems against databases of known vulnerabilities identified by Common Vulnerabilities and Exposures (CVE) numbers and scored with the Common Vulnerability Scoring System (CVSS). It is broad, frequent and relatively safe. A penetration test goes further: skilled testers attempt to exploit weaknesses, chain them together and demonstrate real impact, such as reaching sensitive data. It is deeper, narrower, more expensive and carries more operational risk.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan