nerdexam
(ISC)2

CAP · Question #35

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur?

The correct answer is B. Phase 3. This question reinforces the DITSCAP framework. ST&E (Security Test and Evaluation) is the formal process of testing a system against its security requirements to determine whether it meets those requirements in practice. This occurs in Phase 3 (Validation), where the completed…

Assessment/Audit of Security and Privacy Controls

Question

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur?

Options

  • APhase 2
  • BPhase 3
  • CPhase 1
  • DPhase 4

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    93% (57)
  • C
    2% (1)
  • D
    2% (1)

Explanation

This question reinforces the DITSCAP framework. ST&E (Security Test and Evaluation) is the formal process of testing a system against its security requirements to determine whether it meets those requirements in practice. This occurs in Phase 3 (Validation), where the completed information system is actively tested in its actual or representative operating environment. Phase 2 (Verification) checks the design on paper, but Phase 3 physically validates the built system through hands-on testing-including ST&E activities like vulnerability scanning, functional testing, and penetration testing.

Topics

#DITSCAP#Security Test and Evaluation#ST&E#System assessment

Community Discussion

No community discussion yet for this question.

Full CAP Practice