Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 878 discussion

Actual exam question from Isaca's CISM
Question #: 878
Topic #: 1
[All CISM Questions]

Which of the following BEST minimizes information security risk in deploying applications to the production environment?

  • A. Conducting penetration testing post implementation
  • B. Having a well-defined change process
  • C. Verifying security during the testing process
  • D. Integrating security controls in each phase of the life cycle
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
AaronS1990
Highly Voted 1 year, 2 months ago
Selected Answer: D
I agree this is definitely D. Every other question of this nature emphasises the importance of implementing security as often and early as possible in development.
upvoted 5 times
...
03allen
Most Recent 4 months ago
Selected Answer: B
No doubt, it's B.
upvoted 1 times
...
yottabyte
8 months ago
Selected Answer: B
I will go for B with this one, if the question asks while developing, then the answer will be D, but when the question says deploying, the answer should be B.
upvoted 1 times
...
oluchecpoint
8 months, 1 week ago
Selected Answer: B
Option B
upvoted 1 times
...
Marcelus1714
9 months, 1 week ago
Selected Answer: B
It talk about "risk" (Not "vulnerabilities") and "in deploying", so I would agree the marked answer. If was talking about to detect vulnerabilities in the code, definetly would be D, but B is more high level and related to risks
upvoted 1 times
Marcelus1714
9 months, 1 week ago
and in the change process D can be included
upvoted 1 times
...
...
POWNED
9 months, 3 weeks ago
Selected Answer: B
You have to look at the scope of the question! It is specifically asking what is BEST for deployment to production. Yes Implementing security through the SDLC is the MOST beneficial, but for the scope of the question it is not the best. A properly designed change management process is the best action when it comes to deploying anything new.
upvoted 3 times
...
AlexJacobson
9 months, 3 weeks ago
Selected Answer: B
Well, I'm not so sure it's D. The question is about the deployment to production (from development, I assume). Option D considers SDLC, so it would reduce the risk of introducing vulnerabilities in the application itself. And while one can argue that by increasing the security of the application that you're deploying in production effectively lowers the risk in general, the question is still about the PROCESS of moving something from one environment to another (i.e. the managing the changes in the environment), not the SDLC. So I'm going with B on this one.
upvoted 3 times
AlexJacobson
9 months, 3 weeks ago
Then again, SDLC covers all phases and would include secure implementation and maintenance...So it can be D as well... Tricky question.
upvoted 2 times
...
...
richck102
1 year, 1 month ago
D. Integrating security controls in each phase of the life cycle
upvoted 2 times
...
6and0
1 year, 2 months ago
Selected Answer: D
D. Integrating security controls in each phase of the life cycle
upvoted 2 times
...
Saisharan
1 year, 3 months ago
Option D
upvoted 2 times
...
Ewunia
1 year, 3 months ago
Selected Answer: D
i will go with D
upvoted 4 times
...
AidanSun
1 year, 3 months ago
D should be the correct answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...