Domain 6 · 12%

Security Assessment & Testing

Đánh giá & Kiểm thử Bảo mật

Domain 6 covers security testing methodologies, OWASP vulnerabilities, audit frameworks, and security metrics. Critical for understanding how to measure and verify security controls.

12%

Exam Weight

Domain Progress

0 / 5 lessons complete

5 Lessons

Key Domain 6 Exam Themes

Written authorization required before any pen test — verbal is not sufficient.
OWASP A01 (2021) is Broken Access Control, not Injection (#3).
CVSS Critical (9.0-10.0) must be remediated within 24-48 hours.
SOC 2 Type 2 proves controls worked over time (6-12 months) — more valuable than Type 1.
SAST = source code; DAST = live app; SCA = third-party libraries.
Tabletop = least disruptive DR test; full interruption = most realistic.