- Home
- All questions
- Question 31
CISSP study material · question 31 of 500
A vendor tells a procurement team that its hardware security module is "FIPS validated" because its AES implementation passed algorithm testing. The security engineer reviewing the claim explains that cryptographic module validation under FIPS 140-3 examines considerably more than algorithm correctness. Which areas does that validation cover? Choose two.
Show the answer
Answer: B. The physical security of the module's enclosure and tamper response
D. The module's handling and zeroisation of sensitive security parameters
Module validation covers physical security, the operating environment, non-invasive attack resistance and sensitive security parameter handling; operator identity proofing and organisational risk registers sit outside the module boundary.
Source: NIST FIPS 140-3 (NIST) — FIPS 140-3 > Abstract