CGRC · Question #481
What are the 2 activities involved in certification testing? Response:
The correct answer is A. Assessment of controls, Documentation of Results. Certification testing primarily involves two key activities: the assessment of security controls and the comprehensive documentation of the assessment results.
Question
What are the 2 activities involved in certification testing? Response:
Options
- AAssessment of controls, Documentation of Results
- BAssessment of controls
- CSecurity Controls Assessment
- DSecurity Controls Assessment, Documentation of Results
How the community answered
(23 responses)- A91% (21)
- B4% (1)
- C4% (1)
Why each option
Certification testing primarily involves two key activities: the assessment of security controls and the comprehensive documentation of the assessment results.
Certification testing, as part of the Authorization and Accreditation (A&A) process, fundamentally includes the assessment of security controls to determine their effectiveness and compliance with requirements. Following this assessment, thorough documentation of the results is crucial, outlining findings, vulnerabilities, and the overall security posture to inform the authorization decision.
This choice is incomplete as it only lists 'Assessment of controls' and omits the equally critical activity of documenting results.
'Security Controls Assessment' is essentially the same as 'Assessment of controls' but is still only one of the two primary activities involved in certification testing.
This choice is identical to A, meaning it is also correct. If only one answer is expected, A serves the purpose.
Concept tested: Certification testing activities
Source: csrc.nist.gov/publications/detail/sp/800-37/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.