Due to a high volume of customer orders, an organization plans to implement a new application for customers to use for online ordering. Which type of testing is MOST important to ensure the security of the application prior to go-live?
Stress testing is one of the most useful software testing procedures since it helps the team to assure the product's performance. Furthermore, it verifies the software's security, dependability, and error-handling capabilities, further enhancing its quality
Vulnerability testing is essential for identifying and addressing potential security weaknesses in the application before it is deployed. This testing helps uncover vulnerabilities that could be exploited by attackers, ensuring that any weaknesses are mitigated and that sensitive customer data is protected. Given the high volume of customer orders expected, ensuring the application is secure from cyber threats is critical to maintaining customer trust and compliance with regulatory standards.
C. Vulnerability testing is to ensure the security of the application. It can't be A. Searching on CISA ISACA Ref. Manual 27th ed. we find two occurences of the term "stress testing".
1) "3.5.1 Testing Classifications"
- Stress Testing: Studying the impact on the application by testing with an incremental number of concurrent users/services on the application to determine the maximum number of concurrent users/services the application can process
2) Glossary
C - Capacity stress testing: Testing an application with large quantities of data to evaluate its
performance during peak periods. Also called volume testing.
Also searching the ISACA site on google ( search operator site:isaca.org ) doesn't give any indication that stress testing could have something to do with security.
Software stress tests are designed and performed to identify vulnerabilities, weaknesses, and potential failures that may occur when a system is subjected to intense loads and adverse conditions.
Vulnerability testing is specifically designed to identify weaknesses and security flaws in the application that could be exploited by attackers. So , right answer is C
CCCCCCCCCCCCCCCC
if they ask for "ensure the security of the application" it has to be vulnerability testing
stress testing has nothing to do with security
A is the answer.. security also addresses system availability. the issue here is if the system will handle the voluminous orders
upvoted 5 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Davolee
Highly Voted 2 years, 1 month agoPurpleParrot
Most Recent 3 months agoRS66
4 months, 2 weeks agoanaluisamoreira
4 months, 3 weeks agotopikal
5 months, 1 week ago46080f2
5 months, 3 weeks agoSwallows
7 months, 1 week agoSibsankar
8 months, 3 weeks agoRachy
10 months, 1 week agoJustCisa
1 year agooldmagic
1 year, 4 months ago3008
1 year, 6 months agoJulianleehk
1 year, 11 months agoMunaM
2 years, 2 months agoZephaniah
2 years, 2 months ago