exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 35 discussion

Actual exam question from ISC's CISSP
Question #: 35
Topic #: 1
[All CISSP Questions]

When auditing the Software Development Life Cycle (SDLC) which of the following is one of the high-level audit phases?

  • A. Planning
  • B. Risk assessment
  • C. Due diligence
  • D. Requirements
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
franbarpro
Highly Voted 2 years, 4 months ago
Selected Answer: D
I am thinking "D" - I don't like this question. DLC Phases The entire SDLC process divided into the following SDLC steps: Phase 1: Requirement collection and analysis Phase 2: Feasibility study Phase 3: Design Phase 4: Coding Phase 5: Testing Phase 6: Installation/Deployment Phase 7: Maintenance The requirement is the first stage in the SDLC process. It is conducted by the senior team members with inputs from all the stakeholders and domain experts in the industry. Planning for the quality assurance requirements and recognization of the risks involved is also done at this stage. This stage gives a clearer picture of the scope of the entire project and the anticipated issues, opportunities, and directives which triggered the project. Requirements Gathering stage need teams to get detailed and precise requirements. This helps companies to finalize the necessary timeline to finish the work of that system. https://www.guru99.com/software-development-life-cycle-tutorial.html#3
upvoted 16 times
1460168
6 months ago
Requirements are part of the "Planning"-Phase.
upvoted 2 times
...
dumdada
1 year, 7 months ago
Read the question again
upvoted 2 times
...
jackdryan
1 year, 9 months ago
A is correct.
upvoted 2 times
...
...
explorer3
Highly Voted 2 years, 3 months ago
Selected Answer: A
Planning is an audit phase
upvoted 9 times
...
Fouad777
Most Recent 2 months, 2 weeks ago
The answer is A. Planning. Here's a breakdown of the high-level audit phases within an SDLC audit: Planning: This phase involves defining the audit's scope, objectives, and methodology. It includes identifying the specific areas of the SDLC to be audited, such as requirements gathering, design, development, testing, and deployment. Execution: This phase involves conducting the actual audit, which may include reviewing documentation, interviewing stakeholders, and performing tests. Reporting: This phase involves documenting the audit findings, including any identified issues or risks. The report is typically shared with management and other relevant stakeholders. While risk assessment and due diligence are important aspects of software development, they are not typically considered high-level audit phases. Requirements are part of the SDLC but are not an audit phase.
upvoted 1 times
...
celomomo
4 months ago
Selected Answer: A
In the context of auditing the SDLC, Planning is a high-level audit phase that is critical for setting the direction and scope of the audit. It lays the groundwork for the audit team's approach and ensures that all subsequent activities are aligned with the audit objectives.
upvoted 1 times
...
robervalchocolat
5 months ago
The high-level audit phases typically include: Planning: This phase involves defining the scope of the audit, identifying objectives, and developing an audit plan. Execution: This phase involves collecting evidence, conducting interviews, and reviewing documentation. Reporting: This phase involves analyzing the evidence, drafting the audit report, and communicating findings to management. Therefore, planning is one of the high-level audit phases when auditing the SDLC.
upvoted 1 times
...
Ramye
7 months, 3 weeks ago
The question is - which of the following is a high level audit phase? So Due Diligence appears to be high-level. So the given answer probably correct but would like to confirm this.
upvoted 1 times
...
CCNPWILL
8 months ago
Selected Answer: D
D. documentation supports D as the correct answer.
upvoted 1 times
...
duplexjay
8 months ago
D is correct. Read page 767 of the Official CISSP CBK Reference, (6th editon).
upvoted 1 times
...
GuardianAngel
12 months ago
Answer: Planning GENERAL SDLC AUDIT PROCEDURE: plan/prepare, describe process, evaluate/report, followup Slide 17 https://s3.amazonaws.com/kajabi-storefronts-production/file-uploads/sites/69255/themes/2154025622/downloads/50fa5a8-d4c-27cf-08cb-023ecccc54e3_Monica_Chis-SDLC-AUDIT-AUGUST-9.pdf
upvoted 1 times
...
Kugan
1 year ago
Selected Answer: C
A/D are the same meaning, Planning is part of requirement. Answer is C because its part of Due diligence in auditing process
upvoted 2 times
...
GPrep
1 year ago
Selected Answer: A
A - Plan is the only one listed - https://aws.amazon.com/what-is/sdlc/#:~:text=The%20software%20development%20lifecycle%20(SDLC,expectations%20during%20production%20and%20beyond.
upvoted 2 times
...
AlexJacobson
1 year, 2 months ago
Selected Answer: D
It is ABSOLUTELY D: Official CISSP CBK (6th edition): Software Development Auditing phases: - Requirements phase - Requirements phase - Implementation phase - Verification phase - Operation and maintenance phase
upvoted 5 times
duplexjay
8 months ago
D is correct
upvoted 1 times
...
...
NameisAlreadyTaken
1 year, 2 months ago
Selected Answer: C
Every option is under the due diligence
upvoted 1 times
...
bluerock2k
1 year, 2 months ago
"A" Question is for "Audit phases" not SDLC steps: Phase 1: Requirement collection and analysis Phase 2: Feasibility study Phase 3: Design Phase 4: Coding Phase 5: Testing Phase 6: Installation/Deployment Phase 7: Maintenance
upvoted 1 times
...
Moose01
1 year, 4 months ago
A. Planning Planning phase also includes requirements, a wish list of the stakeholders/senior management and experts, which at this point the audit will gather all items the will audit as SDLC moves from one phase to the next.
upvoted 3 times
...
74gjd_37
1 year, 4 months ago
Selected Answer: A
The answer is A (Planning). The option D (Requirements) is incorrect because the requirements is not a phase of an AUDIT process.
upvoted 2 times
...
Sledge_Hammer
1 year, 4 months ago
I think it's Planning. The correct answer is A The 5 SDLC Phases: Planning Designing Developing Testing Maintenance
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago