nerdexam
(ISC)2

CSSLP · Question #134

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur?

The correct answer is C. Phase 3. In the Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP), Security Test and Evaluation (ST&E) is conducted during Phase 3, known as the Certification phase. This phase assesses the system's security controls and validates…

Secure Software Testing

Question

In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur?

Options

  • APhase 2
  • BPhase 4
  • CPhase 3
  • DPhase 1

How the community answered

(45 responses)
  • B
    2% (1)
  • C
    93% (42)
  • D
    4% (2)

Why each option

In the Department of Defense Information Technology Security Certification and Accreditation Process (DITSCAP), Security Test and Evaluation (ST&E) is conducted during Phase 3, known as the Certification phase. This phase assesses the system's security controls and validates their implementation.

APhase 2

Phase 2 (Definition) focuses on defining the system security requirements and architecture, not on performing the ST&E.

BPhase 4

Phase 4 (Post Accreditation) involves continuous monitoring and managing changes after the system has received its accreditation, not the initial ST&E.

CPhase 3Correct

Security Test and Evaluation (ST&E) is a critical component of Phase 3, the Certification phase, of the DITSCAP process. During this phase, comprehensive testing is performed to verify that the system's security controls are implemented correctly and effectively.

DPhase 1

Phase 1 (Initiation) involves identifying system boundaries and initiating the C&A process, which precedes the detailed testing.

Concept tested: DITSCAP phases - Certification

Topics

#DITSCAP#Security Test and Evaluation#Certification and Accreditation#Security Assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice