ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 487 - CAS-004 discussion

Report
Export

During the development process, the team identifies major components that need to be rewritten. As a result, the company hires a security consultant to help address major process issues. Which of the following should the consultant recommend to best prevent these issues from reoccurring in the future?

A.
Implementing a static analysis tool within the CI/CD system
Answers
A.
Implementing a static analysis tool within the CI/CD system
B.
Configuring a dynamic application security testing tool
Answers
B.
Configuring a dynamic application security testing tool
C.
Performing software composition analysis on all third-party components
Answers
C.
Performing software composition analysis on all third-party components
D.
Utilizing a risk-based threat modeling approach on new projects
Answers
D.
Utilizing a risk-based threat modeling approach on new projects
E.
Setting up an interactive application security testing tool
Answers
E.
Setting up an interactive application security testing tool
Suggested answer: D

Explanation:

A risk-based threat modeling approach is the best recommendation to prevent the recurrence of major process issues during the development lifecycle. Threat modeling identifies potential security threats, vulnerabilities, and design flaws early in the development process by focusing on the specific risks posed to the system. By proactively identifying and addressing security concerns before they escalate, the development team can avoid the need for significant rewrites and ensure that security is embedded into the design of new projects. CASP+ emphasizes threat modeling as a critical activity to improve secure development practices.

CASP+ CAS-004 Exam Objectives: Domain 2.0 -- Enterprise Security Operations (Threat Modeling and Risk-Based Security Approaches)

CompTIA CASP+ Study Guide: Threat Modeling and Secure Development Lifecycle

asked 02/10/2024
Leandro Zaneratto
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first