exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 312 discussion

Actual exam question from CompTIA's SY0-701
Question #: 312
Topic #: 1
[All SY0-701 Questions]

Which of the following topics would most likely be included within an organization's SDLC?

  • A. Service-level agreements
  • B. Information security policy
  • C. Penetration testing methodology
  • D. Branch protection requirements
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Cee007
Highly Voted 4 months, 1 week ago
Selected Answer: D
D. Branch protection requirements Branch protection requirements are related to the version control and development process within the SDLC, ensuring that code changes are reviewed, tested, and approved before being merged into main branches. This helps maintain code quality and security throughout the development process. Penetration testing is usually conducted as part of the testing phase or after deployment to identify vulnerabilities and security weaknesses. It is a separate process from the core stages of the SDLC but is an important aspect of ensuring the security and robustness of the application once development is completed.
upvoted 5 times
koala_lay
3 months, 4 weeks ago
Agree to answer D.
upvoted 2 times
...
...
jbmac
Most Recent 1 week, 6 days ago
Selected Answer: D
The correct answer is: D. Branch protection requirements Explanation: The Software Development Life Cycle (SDLC) refers to the structured process for planning, creating, testing, and deploying software applications. Among the provided options, branch protection requirements would most likely be included in the SDLC as part of the version control process to ensure that changes to the codebase are reviewed, tested, and securely merged. Branch protection ensures that only authorized and verified code can be merged into critical branches (like the main or master branch), which helps maintain the security, quality, and stability of the software. It often involves using code reviews, automated testing, and other safeguards to protect the integrity of the development process.
upvoted 1 times
...
laternak26
2 weeks, 3 days ago
Selected Answer: D
Branch protection requirements are typically part of the Software Development Life Cycle (SDLC), specifically in the phase where code is managed and controlled. These requirements ensure that the code in version control systems (like Git) is protected from unauthorized or accidental changes. For example, branch protection can enforce rules such as requiring code reviews, preventing direct pushes to the main branch, or ensuring all tests pass before code is merged. These practices help maintain the quality and security of the codebase throughout the development lifecycle.
upvoted 1 times
...
e2ba0ff
1 month ago
Selected Answer: C
SDLC Includes secure coding practices, code reviews, and testing standards
upvoted 1 times
...
Cocopqr
1 month ago
Selected Answer: D
Software Development Life Cycle (SDLC) is a framework that defines the stages involved in developing software. It focuses on the technical aspects of software development, including requirements gathering, design, development, testing, and deployment. Branch protection requirements are directly related to the development process and ensure code quality and security. They typically involve rules for merging code, such as requiring code reviews and preventing direct pushes to the main branch
upvoted 1 times
...
fmeox567
1 month, 2 weeks ago
Selected Answer: C
C. Penetration testing methodology Here's why: The SDLC is a framework that outlines the process for developing, deploying, and maintaining systems or applications. It typically includes phases such as planning, requirements gathering, design, development, testing, deployment, and maintenance. Penetration testing methodology is directly tied to the testing and security assurance phases of the SDLC. Organizations often incorporate security assessments, such as penetration testing, into the development process to identify and mitigate vulnerabilities before deployment. GPT
upvoted 2 times
...
Murtuza
2 months, 3 weeks ago
Selected Answer: C
option like penetration testing methodology would more closely align with SDLC than the overarching Information Security Policy
upvoted 1 times
...
User92
3 months ago
Selected Answer: D
Branch protection requirements are directly related to the software development process, particularly in version control and code management. These requirements help ensure that only reviewed and approved code is merged into the main branch, maintaining the integrity and quality of the software throughout its development lifecycle. Why not B: Information security policy is a broader organizational policy that governs overall security practices. Why not C: Penetration testing methodology is part of security testing but not specifically tied to the SDLC phases.
upvoted 1 times
...
khank14
3 months, 1 week ago
so many different answers
upvoted 1 times
...
dhewa
3 months, 2 weeks ago
Selected Answer: B
This is because an information security policy outlines the guidelines and practices for protecting sensitive data throughout the development process.
upvoted 2 times
...
Lavette
3 months, 3 weeks ago
C. Penetration testing methodology is often part of the SDLC, especially in the testing phase, to identify vulnerabilities in the software before it goes live. While the other options are important in the broader organizational policies and security management, they are not typically a direct part of the SDLC process.
upvoted 1 times
...
cri88
3 months, 3 weeks ago
Selected Answer: B
B. Information security policy An Information security policy is often included within an organization's Software Development Life Cycle (SDLC) because security considerations are critical during the design, development, and deployment phases of software development. The SDLC aims to integrate security measures throughout the process to protect against vulnerabilities and ensure compliance with security standards. Service-level agreements (A) are more related to contracts and service performance rather than the SDLC. Penetration testing methodology (C) is typically used for post-development testing, not a core part of the SDLC. Branch protection requirements (D) relate to source code management and version control, but they are not commonly included as a core topic of the SDLC. Thus, Information security policy aligns most closely with the SDLC's focus on incorporating security best practices throughout the software development process.
upvoted 2 times
...
17f9ef0
4 months ago
Selected Answer: C
Answer is C
upvoted 2 times
...
a4e15bd
4 months ago
Selected Answer: C
The correct answer is C in this context. Pen Testing methodology could be part of the SDLC and directly relevant to the testing and security assurance phases of software development. D is incorrect because Branch Protection Requirements is more related to security measures around the physical or network infrastructure not software development.
upvoted 1 times
...
Ayokunle01
4 months, 1 week ago
B. Information security policy An organization's Software Development Life Cycle (SDLC) typically includes information security policy to ensure that software development aligns with the organization's overall security posture. This policy outlines security requirements, standards, and guidelines for software development.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago