HP Security & Compliance Standards 3 — Questions and Answers
Question 1: An organization needs HP devices to comply with Common Criteria (CC) evaluation. What does a CC certification primarily assure?
- The device meets specific performance benchmarks
- The device's security features have been independently evaluated against defined security requirements (Correct answer)
- The device is approved for use in all NATO countries
- The device firmware is open source and auditable
Correct answer: The device's security features have been independently evaluated against defined security requirements
Common Criteria certification means an independent lab has evaluated the product against a defined Security Target and Protection Profile, providing assurance of security claims.
Question 2: HP Sure Click uses which technology to isolate potentially malicious web content?
- Virtual private network tunneling
- Micro-virtual machine (micro-VM) isolation (Correct answer)
- Sandboxed JavaScript engine
- Mandatory Access Control (MAC) policies
Correct answer: Micro-virtual machine (micro-VM) isolation
HP Sure Click opens each browser tab or downloaded file in a disposable micro-VM, so any malware is discarded when the tab closes.
Question 3: Which HP security feature continuously monitors critical OS processes at runtime to detect and stop tampering?
- HP Sure Start
- HP Sure Run (Correct answer)
- HP Sure Click
- HP Sure Sense
Correct answer: HP Sure Run
HP Sure Run monitors protected processes at runtime, detecting and recovering from tampering even if malware attempts to kill security agents.
Question 4: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the relevant supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires organizations to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 5: HP Secure Erase for hard drives is designed to meet which standard for data sanitization?
- NIST SP 800-88 (Correct answer)
- ISO 27001 Annex A
- FIPS 140-2
- PCI DSS Requirement 3
Correct answer: NIST SP 800-88
NIST SP 800-88 'Guidelines for Media Sanitization' is the standard HP Secure Erase is designed to comply with for drive data destruction.
Question 6: Which type of attack does HP Sure Sense primarily defend against using AI-based detection?
- Phishing emails targeting credentials
- Zero-day malware and polymorphic threats (Correct answer)
- SQL injection on web applications
- Man-in-the-middle network attacks
Correct answer: Zero-day malware and polymorphic threats
HP Sure Sense uses deep learning AI to detect and block zero-day malware and polymorphic threats that signature-based AV cannot identify.
Question 7: In HP's security portfolio, what is the purpose of HP Connection Inspector?
- Scanning USB devices for malware before mounting
- Analyzing network connections to detect command-and-control traffic (Correct answer)
- Verifying digital certificates for HTTPS websites
- Monitoring printer firmware for unauthorized changes
Correct answer: Analyzing network connections to detect command-and-control traffic
HP Connection Inspector monitors network traffic patterns from endpoints to identify suspicious outbound connections indicative of malware C2 communications.
An organization needs HP devices to comply with Common Criteria (CC) evaluation.
What does a CC certification primarily assure?