nerdexam
(ISC)2

CSSLP · Question #275

Security Test and Evaluation (ST&E) is a component of risk assessment. It is useful in discovering system vulnerabilities. For what purposes is ST&E used? Each correct answer represents a complete…

The correct answer is B. To determine the adequacy of security mechanisms, assurances, and other properties to enforce the C. To assess the degree of consistency between the system documentation and its implementation D. To uncover design, implementation, and operational flaws that may allow the violation of security policy. Security Test and Evaluation (ST&E) is employed to ascertain the effectiveness of security mechanisms, verify consistency between system documentation and actual implementation, and detect design, implementation, or operational flaws that could lead to security policy violations.

Secure Software Testing

Question

Security Test and Evaluation (ST&E) is a component of risk assessment. It is useful in discovering system vulnerabilities. For what purposes is ST&E used? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ATo implement the design of system architecture
  • BTo determine the adequacy of security mechanisms, assurances, and other properties to enforce the
  • CTo assess the degree of consistency between the system documentation and its implementation
  • DTo uncover design, implementation, and operational flaws that may allow the violation of security policy

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    87% (27)

Why each option

Security Test and Evaluation (ST&E) is employed to ascertain the effectiveness of security mechanisms, verify consistency between system documentation and actual implementation, and detect design, implementation, or operational flaws that could lead to security policy violations.

ATo implement the design of system architecture

ST&E is an evaluation activity that occurs after design and implementation phases to verify security, rather than being a step involved in the active implementation of system architecture design itself.

BTo determine the adequacy of security mechanisms, assurances, and other properties to enforce theCorrect

ST&E directly assesses whether the implemented security mechanisms, such as controls and assurances, are sufficiently robust and correctly configured to enforce the established security policies and requirements.

CTo assess the degree of consistency between the system documentation and its implementationCorrect

ST&E involves comparing system documentation (e.g., security plans, design documents) with the actual deployed system to identify any inconsistencies or deviations in security implementation.

DTo uncover design, implementation, and operational flaws that may allow the violation of security policyCorrect

A primary purpose of ST&E is to systematically identify and uncover vulnerabilities, weaknesses, or flaws across the system's design, implementation, and operational phases that could be exploited to violate security policies.

Concept tested: Purposes of Security Test and Evaluation (ST&E)

Source: https://csrc.nist.gov/glossary/term/security_test_and_evaluation

Topics

#Security Test and Evaluation#Vulnerability Assessment#Security Policy Enforcement#Security Controls Adequacy

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice