PrepAway - Latest Free Exam Questions & Answers

Which of the following BEST describes Configuration Man…

Which of the following BEST describes Configuration Management controls?

PrepAway - Latest Free Exam Questions & Answers

A.
Auditing of changes to the Trusted Computing Base.

B.
Control of changes to the Trusted Computing Base.

C.
Changes in the configuration access to the Trusted Computing Base.

D.
Auditing and controlling any changes to the Trusted Computing Base.

Explanation:
Configuration management consists of identifying, controlling, accounting for, and auditing all changes made to
a particular system or equipment during its life cycle. In particular, as related to equipment used to process
classified information, equipment can be identified in categories of COMSEC, TEMPEST, or as a Trusted
Computer Base (TCB).
The Trusted Computer System Evaluation Criteria (TCSEC) requires all changes to the TCB for classes B2
through A1 be controlled by configuration management. Although the “rainbow series” documentation mostly
relates to software controls for trusted computers, configuration management is not limited to only this function.
Incorrect Answers:
A: Configuration Management is not just the auditing of changes to the Trusted Computing Base; it also
includes controlling any changes to the TCB.
B: Configuration Management is not just the control of changes to the Trusted Computing Base; it also includes
the auditing of changes to the TCB.
C: Configuration Management is not defined as the control of changes in the configuration access to the
Trusted Computing Base.

http://surflibrary.org/ses/TEMPBOOK/CH6CONFGMGT.pdf


Leave a Reply