Study. uk . com
  1. Home
  2. All questions
  3. Question 230

CISSP study material · question 230 of 500

An architect specifies FIPS 140-3 Level 4 for every module in a low-impact internal application, arguing that higher is always safer. What does the standard advise?

  1. Level 1 is the maximum permitted for software modules regardless of need.
  2. The level should be chosen to match the security the application and environment actually require.
  3. Level 4 is required wherever cryptography protects sensitive information.
  4. The level is fixed by the algorithm the module implements.
Show the answer

Answer: B. The level should be chosen to match the security the application and environment actually require.

FIPS 140-3 says the level to which a module is validated must be chosen to provide security appropriate for the requirements of the application and environment and the services provided.

Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > 7. Applications

Challenge yourself on this topic → Study as cards