nerdexam
EC-Council

312-50V9 · Question #42

What is the name of the international standard that establishes a baseline level of confidence in the security functionality of IT products by providing a set of requirements for evaluation?

The correct answer is C. Common Criteria. Common Criteria (ISO/IEC 15408) is the internationally recognized framework that defines Evaluation Assurance Levels (EALs) and security functional requirements for assessing IT product security.

Introduction to Ethical Hacking

Question

What is the name of the international standard that establishes a baseline level of confidence in the security functionality of IT products by providing a set of requirements for evaluation?

Options

  • ABlue Book
  • BISO 26029
  • CCommon Criteria
  • DThe Wassenaar Agreement

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    88% (21)

Why each option

Common Criteria (ISO/IEC 15408) is the internationally recognized framework that defines Evaluation Assurance Levels (EALs) and security functional requirements for assessing IT product security.

ABlue Book

The 'Blue Book' is informal terminology sometimes applied to various government documents; it does not refer to a recognized international IT security evaluation standard.

BISO 26029

ISO 26029 is not the standard for IT security product evaluation - the correct ISO standard for this purpose is ISO/IEC 15408, which is Common Criteria.

CCommon CriteriaCorrect

Common Criteria, formally known as ISO/IEC 15408, is the international standard that provides a structured set of security functional requirements and assurance requirements used by independent testing laboratories to evaluate IT products. It establishes Evaluation Assurance Levels (EAL1 through EAL7) that define the depth and rigor of the evaluation, giving buyers and governments a standardized basis for trusting IT product security claims.

DThe Wassenaar Agreement

The Wassenaar Arrangement is a multilateral export control regime that governs trade in dual-use goods and munitions including certain security technologies, not a framework for evaluating IT product security functionality.

Concept tested: Common Criteria ISO/IEC 15408 IT security evaluation standard

Source: https://www.commoncriteriaportal.org/cc/

Topics

#Common Criteria#IT security standards#product evaluation#security certification

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice