ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is considering a cloud service provider that claims its hardware security modules (HSMs) have been certified at "Level 3" to satisfy U.S. government requirements for protecting encryption keys at rest. To confirm that the provider's HSMs meet the appropriate system/sub-system product certification, which document or designation should you request from the provider?
A recent SOC 2 Type II report for the provider's overall cloud platform.
A Common Criteria certificate showing Evaluation Assurance Level 4+ for the HSM firmware.
The module's FIPS 140-2 Level 3 validation certificate and CMVP validation report.
An ISO/IEC 27018 conformity statement covering protection of personally identifiable information.
Under the U.S. and Canadian Cryptographic Module Validation Program (CMVP), cryptographic modules such as HSMs are tested against the Federal Information Processing Standard (FIPS) 140-2. The standard defines four increasing assurance levels; Level 3 adds physical tamper-resistance and identity-based authentication-controls commonly required for government workloads handling sensitive data. Therefore, the correct evidence is the provider's specific FIPS 140-2 Level 3 validation certificate and the associated CMVP report. A Common Criteria Evaluation Assurance Level (EAL) certificate, ISO/IEC 27018 statement, or a SOC 2 Type II report may attest to other security controls or privacy practices, but none of them verifies compliance with the cryptographic requirements of FIPS 140-2.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS 140-2 Level 3 validation?
Open an interactive chat with Bash
What is the Cryptographic Module Validation Program (CMVP)?
Open an interactive chat with Bash
How does FIPS 140-2 differ from Common Criteria EAL certification?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .