CSSLP · Question #275
Security Test and Evaluation (ST&E) is a component of risk assessment. It is useful in discovering system vulnerabilities. For what purposes is ST&E used? Each correct answer represents a complete…
The correct answer is B. To determine the adequacy of security mechanisms, assurances, and other properties to enforce the C. To assess the degree of consistency between the system documentation and its implementation D. To uncover design, implementation, and operational flaws that may allow the violation of security policy. Security Test and Evaluation (ST&E) is employed to ascertain the effectiveness of security mechanisms, verify consistency between system documentation and actual implementation, and detect design, implementation, or operational flaws that could lead to security policy violations.
Question
Security Test and Evaluation (ST&E) is a component of risk assessment. It is useful in discovering system vulnerabilities. For what purposes is ST&E used? Each correct answer represents a complete solution. Choose all that apply.
Options
- ATo implement the design of system architecture
- BTo determine the adequacy of security mechanisms, assurances, and other properties to enforce the
- CTo assess the degree of consistency between the system documentation and its implementation
- DTo uncover design, implementation, and operational flaws that may allow the violation of security policy
How the community answered
(31 responses)- A13% (4)
- B87% (27)
Why each option
Security Test and Evaluation (ST&E) is employed to ascertain the effectiveness of security mechanisms, verify consistency between system documentation and actual implementation, and detect design, implementation, or operational flaws that could lead to security policy violations.
ST&E is an evaluation activity that occurs after design and implementation phases to verify security, rather than being a step involved in the active implementation of system architecture design itself.
ST&E directly assesses whether the implemented security mechanisms, such as controls and assurances, are sufficiently robust and correctly configured to enforce the established security policies and requirements.
ST&E involves comparing system documentation (e.g., security plans, design documents) with the actual deployed system to identify any inconsistencies or deviations in security implementation.
A primary purpose of ST&E is to systematically identify and uncover vulnerabilities, weaknesses, or flaws across the system's design, implementation, and operational phases that could be exploited to violate security policies.
Concept tested: Purposes of Security Test and Evaluation (ST&E)
Source: https://csrc.nist.gov/glossary/term/security_test_and_evaluation
Topics
Community Discussion
No community discussion yet for this question.