ExamGecko
Question list
Search
Search

Related questions

Question 148 - CISA discussion

Report
Export

Secure code reviews as part of a continuous deployment program are which type of control?

A.
Detective
Answers
A.
Detective
B.
Logical
Answers
B.
Logical
C.
Preventive
Answers
C.
Preventive
D.
Corrective
Answers
D.
Corrective
Suggested answer: C

Explanation:

Secure code reviews as part of a continuous deployment program are preventive controls. Preventive controls are controls that aim to prevent or avoid undesirable events or outcomes from occurring, such as errors, defects, or incidents. Secure code reviews are activities that examine and evaluate the source code of a software or application to identify and eliminate any vulnerabilities, flaws, or weaknesses that may compromise its security, functionality, or performance. Secure code reviews as part of a continuous deployment program can help prevent or avoid security issues or incidents from occurring by ensuring that the code is secure and compliant before it is deployed to production. The other options are not correct types of controls for secure code reviews as part of a continuous deployment program, as they have different meanings and functions. Detective controls are controls that aim to detect or discover undesirable events or outcomes that have occurred, such as errors, defects, or incidents. Logical controls are controls that use software or hardware mechanisms to regulate or restrict access to IT resources, such as data, systems, or networks. Corrective controls are controls that aim to correct or rectify undesirable events or outcomes that have occurred, such as errors, defects, or incidents.Reference:CISA Review Manual (Digital Version), Chapter 3, Section 3.2

asked 18/09/2024
Carol Mejía
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first