CAS-002 · Question #596
An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed the vendor choices down to two platforms. The integrator chosen to assist the organization with the…
The correct answer is B. Develop testing criteria and evaluate each environment in-house. Developing in-house testing criteria is the most comprehensive evaluation method because it tests platforms against the organization's own environment and requirements rather than external or vendor-controlled conditions.
Question
An organization is preparing to upgrade its firewall and NIPS infrastructure and has narrowed the vendor choices down to two platforms. The integrator chosen to assist the organization with the deployment has many clients running a mixture of the possible combinations of environments. Which of the following is the MOST comprehensive method for evaluating the two platforms?
Options
- ABenchmark each possible solution with the integrators existing client deployments.
- BDevelop testing criteria and evaluate each environment in-house.
- CRun virtual test scenarios to validate the potential solutions.
- DUse results from each vendor's test labs to determine adherence to project requirements.
How the community answered
(28 responses)- A7% (2)
- B75% (21)
- C14% (4)
- D4% (1)
Why each option
Developing in-house testing criteria is the most comprehensive evaluation method because it tests platforms against the organization's own environment and requirements rather than external or vendor-controlled conditions.
Benchmarking against an integrator's existing clients introduces variability since those environments may have different traffic profiles, topologies, and requirements from the organization being evaluated.
In-house evaluation with organization-defined criteria ensures testing reflects actual network topology, traffic characteristics, and security policies unique to that environment. This eliminates vendor bias and integrator client variability, producing results directly applicable to the organization's specific deployment scenario.
Virtual test scenarios may not accurately simulate real-world conditions such as actual traffic volume, hardware performance, or complex integration dependencies.
Vendor test lab results are biased toward favorable outcomes for their own products and are unlikely to address the organization's specific operational requirements.
Concept tested: Security platform evaluation using in-house testing criteria
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Topics
Community Discussion
No community discussion yet for this question.