nerdexam
CompTIA

CAS-001 · Question #121

A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of…

The correct answer is D. To allow certifiers to verify the network meets applicable security requirements. A Security Requirements Traceability Matrix (SRTM) is a document that maps every security requirement - drawn from regulatory mandates, corporate policy, and functional/performance specifications - to the specific design controls, implementation artifacts, or test cases that…

Enterprise Security

Question

A team of security engineers has applied regulatory and corporate guidance to the design of a corporate network. The engineers have generated an SRTM based on their work and a thorough analysis of the complete set of functional and performance requirements in the network specification. Which of the following BEST describes the purpose of an SRTM in this scenario?

Options

  • ATo ensure the security of the network is documented prior to customer delivery
  • BTo document the source of all functional requirements applicable to the network
  • CTo facilitate the creation of performance testing metrics and test plans
  • DTo allow certifiers to verify the network meets applicable security requirements

How the community answered

(43 responses)
  • A
    16% (7)
  • B
    9% (4)
  • C
    5% (2)
  • D
    70% (30)

Explanation

A Security Requirements Traceability Matrix (SRTM) is a document that maps every security requirement - drawn from regulatory mandates, corporate policy, and functional/performance specifications - to the specific design controls, implementation artifacts, or test cases that satisfy it. Its core purpose is auditability and verification: it gives certifiers, auditors, and accreditation authorities a structured way to confirm that every applicable security requirement has been addressed in the final design. Option A is partially true but describes documentation as a delivery artifact rather than the matrix's function. Option B describes only one input (source of requirements), not the purpose of the full traceability chain. Option C conflates performance testing metrics with security traceability - those are separate activities. Option D correctly identifies that the SRTM exists so that an independent party (certifier) can trace requirements through to their implementation and verify compliance.

Topics

#SRTM#security requirements#compliance verification#security architecture

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice