exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 156 discussion

Actual exam question from Isaca's CISM
Question #: 156
Topic #: 1
[All CISM Questions]

During which stage of the software development life cycle (SDLC) should application security controls FIRST be addressed?

  • A. Software code development
  • B. Configuration management
  • C. Requirements gathering
  • D. Application system design
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
chanke
1 month ago
Selected Answer: C
bake-in-security... It should be from the very beginning of the lifecycle.
upvoted 2 times
...
wello
1 month, 1 week ago
Selected Answer: C
As early as possible.
upvoted 1 times
...
richck102
1 month, 1 week ago
C. Requirements gathering
upvoted 1 times
...
dark_3k03r
2 months ago
Selected Answer: C
The correct answer is (C) Requirements Gathering as this is literally the first phase of the SDLC. The SDLC phases are in the following order: - Planning and Analysis - Requirements Gathering - Design - Development - Testing - Deployment - Maintenance
upvoted 3 times
...
Abhey
2 months, 3 weeks ago
Selected Answer: C
The correct answer is C. Requirements gathering. This is the stage of the software development life cycle where application security controls should be first addressed to ensure that security is built into the application from the start. This involves identifying potential security risks and defining security requirements and specifications for the application. This helps to reduce the cost and effort of fixing security issues later in the SDLC, and ensures that the application is developed with security in mind.
upvoted 1 times
...
Nutben
2 months, 3 weeks ago
Security should always be considered from the beginning of the project until its conclusion.
upvoted 1 times
...
adamshup
3 months, 1 week ago
Selected Answer: A
Answer is A
upvoted 1 times
...
bambs
3 months, 1 week ago
Selected Answer: A
Application security controls should be addressed during the software code development stage of the software development life cycle (SDLC). At this stage, the code is being written, and security controls such as input validation, output encoding, and authentication can be integrated into the code. By addressing security controls early in the SDLC, it becomes easier to identify and remediate potential security vulnerabilities before the application is deployed in production.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago