nerdexam
(ISC)2

CISSP · Question #677

Which of the following is a security weakness in the evaluation of common criteria (CC) products?

The correct answer is A. The manufacturer can state what configuration of the product is to be evaluated. Under Common Criteria, the manufacturer (or sponsor) defines the Security Target (ST) and the specific configuration of the product that will be evaluated as the Target of Evaluation (TOE). This creates a weakness because the vendor can: Choose a limited or hardened…

Submitted by renata2k· Mar 5, 2026Security Assessment and Testing

Question

Which of the following is a security weakness in the evaluation of common criteria (CC) products?

Options

  • AThe manufacturer can state what configuration of the product is to be evaluated.
  • BThe product can be evaluated by labs m other countries.
  • CThe Target of Evaluation's (TOE) testing environment is identical to the operating environment
  • DThe evaluations are expensive and time-consuming to perform.

How the community answered

(23 responses)
  • A
    83% (19)
  • B
    4% (1)
  • C
    9% (2)
  • D
    4% (1)

Explanation

Under Common Criteria, the manufacturer (or sponsor) defines the Security Target (ST) and the specific configuration of the product that will be evaluated as the Target of Evaluation (TOE). This creates a weakness because the vendor can: Choose a limited or hardened configuration that is not representative of how the product is actually deployed in real environments. Exclude certain features, interfaces, or modes of operation from the evaluation, which may hide real‑world vulnerabilities. This undermines the meaningfulness of the evaluation and can give a false sense of security if the certified configuration differs from the one used in production.

Topics

#Common Criteria#product evaluation#security testing#certification

Community Discussion

No community discussion yet for this question.

Full CISSP Practice