Study. uk . com
  1. Home
  2. All questions
  3. Question 253

CISSP study material · question 253 of 500

A supplier states its module either passes or fails FIPS 140-3 validation. How does the standard actually grade modules?

  1. On four increasing qualitative levels of security.
  2. On three levels aligned to the FIPS 199 impact scale.
  3. On a numeric score from one to one hundred.
  4. On a pass or fail basis, with an optional physical security annex.
Show the answer

Answer: A. On four increasing qualitative levels of security.

FIPS 140-3 provides four increasing qualitative levels of security, intended to cover the range of applications and environments in which modules may be deployed.

Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > Abstract

Challenge yourself on this topic → Study as cards