ISC Certified Secure Software Lifecycle Professional CSSLP Question # 92 Topic 10 Discussion

ISC Certified Secure Software Lifecycle Professional CSSLP Question # 92 Topic 10 Discussion

CSSLP Exam Topic 10 Question 92 Discussion:
Question #: 92
Topic #: 10

Security Test and Evaluation (ST&E) is a component of risk assessment. It is useful in discovering system vulnerabilities. For what purposes is ST&E used? Each correct answer represents a complete solution. Choose all that apply.


A.

To implement the design of system architecture


B.

To determine the adequacy of security mechanisms, assurances, and other properties to enforce the security policy


C.

To assess the degree of consistency between the system documentation and its implementation


D.

To uncover design, implementation, and operational flaws that may allow the violation of security policy


Get Premium CSSLP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.