🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization is planning to purchase a hardware security module (HSM) to store production encryption keys for a new payment-processing system. Corporate policy states that any device entrusted with key custody must be validated to at least FIPS 140-3 Level 3. As the security practitioner assigned to the acquisition effort, which action will most effectively ensure that only products meeting this security requirement are considered during procurement?

  • Accept a signed statement from the vendor that its HSM is FIPS 140-3 compliant, and schedule independent testing after installation is complete.

  • Specify the FIPS 140-3 Level 3 requirement in the RFP and require vendors to submit their NIST validation certificates with their bids.

  • Select the lowest-priced HSM and plan to deploy software-based encryption controls to compensate for any missing certifications.

  • Postpone all security validation until the first annual audit after the HSMs are in production.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot