Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 190 discussion

Actual exam question from ISC's CISSP
Question #: 190
Topic #: 1
[All CISSP Questions]

In the common criteria, which of the following is a formal document that expresses an implementation-independent set of security requirements?

  • A. Organizational Security Policy
  • B. Security Target (ST)
  • C. Protection Profile (PP)
  • D. Target of Evaluation (TOE)
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DeepCyber
Highly Voted 1 year, 5 months ago
Selected Answer: C
The Common Criteria process is based on two key elements: protection profiles and security targets. Protection profiles (PPs) specify for a product that is to be evaluated (the TOE) the security requirements and protections, which are considered the security desires, or the “I want,” from a customer. Security targets (STs) specify the claims of security from the vendor that are built into a TOE. STs are considered the implemented security measures, or the “I will provide,” from the vendor.
upvoted 6 times
...
Soleandheel
Most Recent 11 months, 2 weeks ago
A formal document that expresses an implementation-independent set of security requirements is called: C. Protection Profile (PP) A Protection Profile (PP) defines security requirements for a specific type of product or system without specifying how those requirements should be implemented. It serves as a baseline set of security requirements that can be used to evaluate and compare products or systems.
upvoted 1 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: C
A Protection Profile (PP) is a vendor-neutral document that defines a set of security requirements common to a specific class of IT products or systems. PPs provide a baseline to evaluate security features or functions of any IT product or system within that class. PPs specify a set of security objectives, threats and countermeasures, whereas a Security Target (ST) is specific to an implementation of an IT product or system and includes implementation-specific details.
upvoted 2 times
...
Tygrond87
1 year, 6 months ago
Selected Answer: B
A Protection Profile (PP) is a document that specifies security requirements for a particular class of information technology products or systems, and can be used as the basis for product or system evaluations. In contrast, a Security Target (ST) is a formal document that expresses a set of security requirements for a specific product or system, and is implementation-dependent. Therefore, the correct answer to the question is B, Security Target (ST).
upvoted 1 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
Pappykay
1 year, 10 months ago
Selected Answer: C
Protection profiles (PPs) specify for a product that is to be evaluated (the TOE) the security requirements and protections, which are considered the security desires or the “I want” from a customer. Security targets (STs) specify the claims of security from the vendor that are built into a TOE
upvoted 3 times
...
DJOEK
1 year, 10 months ago
Selected Answer: C
The Security Target (ST) is a formal document that expresses an implementation-independent set of security requirements in the common criteria. It specifies the security functionality and assurance requirements of a Target of Evaluation (TOE), which is the product or system being evaluated. The ST is used as a reference for evaluating the security capabilities of the TOE and ensuring that it meets the specified security requirements. It is one of the key components of the common criteria evaluation process, along with the Protection Profile (PP) and the Evaluation Assurance Level (EAL). The PP is a document that specifies the security functional and assurance requirements for a particular class of TOEs, while the EAL is a measure of the depth and rigor of the security evaluation conducted on the TOE.
upvoted 2 times
dumdada
1 year, 5 months ago
"The Security Target (ST) is a formal document that expresses an implementation-DEPENDENT", not INDEPENDENT.
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: C
C is correct
upvoted 1 times
...
rdy4u
2 years, 1 month ago
Selected Answer: C
A Protection Profile (PP) is an implementation-independent set of security requirements for a class of Targets of Evaluation (TOEs) that meet specific consumer needs https://www.cisa.gov/uscert/bsi/articles/best-practices/requirements-engineering/the-common-criteria
upvoted 3 times
...
explorer3
2 years, 1 month ago
Selected Answer: C
C is correct, as PP is implementation independent and ST is product specific
upvoted 1 times
...
franbarpro
2 years, 1 month ago
protection profile (pp) is defined as: A minimal, baseline set of requirements targeted at mitigating well defined and described threats. The term Protection Profile refers to NSA/NIAP requirements for a technology and does not imply or require the use of Common Criteria as the process for evaluating a product.
upvoted 1 times
...
gautamzone
2 years, 1 month ago
Selected Answer: B
Shouldn't it be B based on this link? https://en.wikipedia.org/wiki/Common_Criteria Reference Text: Security Target (ST) – the document that identifies the security properties of the target of evaluation
upvoted 1 times
...
brb77
2 years, 2 months ago
C is correct
upvoted 2 times
...
Cww1
2 years, 2 months ago
C is correct
upvoted 2 times
...
gooftroop
2 years, 2 months ago
D. Target of Evaluation (TOE)
upvoted 1 times
DERCHEF2009
2 years, 2 months ago
Wrong its C
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...