ExamGecko
Question list
Search
Search

Related questions

Question 418 - CISA discussion

Report
Export

Which of the following would BEST help to ensure that potential security issues are considered by the development team as part of incremental changes to agile-developed software?

A.
Assign the security risk analysis to a specially trained member of the project management office.
Answers
A.
Assign the security risk analysis to a specially trained member of the project management office.
B.
Deploy changes in a controlled environment and observe for security defects.
Answers
B.
Deploy changes in a controlled environment and observe for security defects.
C.
Include a mandatory step to analyze the security impact when making changes.
Answers
C.
Include a mandatory step to analyze the security impact when making changes.
D.
Mandate that the change analyses are documented in a standard format.
Answers
D.
Mandate that the change analyses are documented in a standard format.
Suggested answer: C

Explanation:

The best way to ensure that potential security issues are considered by the development team as part of incremental changes to agile-developed software is to include a mandatory step to analyze the security impact when making changes. This will help to identify and mitigate any security risks or vulnerabilities that may arise from the changes, and to ensure that the software meets the security requirements and standards.The other options are not as effective, because they either delegate the security analysis to someone outside the development team, rely on post-deployment testing, or focus on documentation rather than analysis.Reference:CISA Review Manual (Digital Version)1, Chapter 4, Section 4.2.5

asked 18/09/2024
Emmanuel Yeboah
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first