Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 37 discussion

Actual exam question from ISC's CISSP
Question #: 37
Topic #: 1
[All CISSP Questions]

Which of the following does the security design process ensure within the System Development Life Cycle (SDLC)?

  • A. Proper security controls, security objectives, and security goals are properly initiated.
  • B. Security objectives, security goals, and system test are properly conducted.
  • C. Proper security controls, security goals, and fault mitigation are properly conducted.
  • D. Security goals, proper security controls, and validation are properly initiated.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
krassko
Highly Voted 2 years, 1 month ago
Selected Answer: A
It can't be D or anything where testing or validation is mentioned. as validation or testing are not part of the design but part of the next phase - implementation.
upvoted 5 times
...
Fouad777
Most Recent 4 days, 13 hours ago
he answer is A. Proper security controls, security objectives, and security goals are properly initiated. The security design process in the SDLC is focused on ensuring that security is baked into the system from the very beginning. This includes:   Initiating security objectives and goals: Clearly defining the security objectives and goals for the system. Defining security controls: Identifying and implementing appropriate security controls to protect the system and its data.   Ensuring proper initiation: Making sure that these security measures are properly initiated and integrated into the development process. While other options may involve important aspects of the SDLC, they do not accurately capture the core focus of the security design process, which is to establish a strong security foundation from the outset.
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: A
In the context of the security design process within the System Development Life Cycle (SDLC), both option A and option D have their merits, but it ultimately depends on the specific needs and requirements of the organization. Option A: Proper security controls, security objectives, and security goals are properly initiated emphasizes the importance of ensuring that the appropriate security controls, objectives, and goals are identified and initiated during the security design process. This option highlights the need for a proactive approach in implementing security measures from the early stages of system development. Option D: Security goals, proper security controls, and validation are properly initiated adds the aspect of validation to the mix. It emphasizes the importance of not only setting security goals and implementing security controls but also ensuring that these controls are validated to ensure their effectiveness and alignment with the desired security objectives. both are valid, as i said earlier, it all depend on the requirements or the need of the company/organization.
upvoted 2 times
...
KelvinYau
1 year, 5 months ago
Selected Answer: A
I think A...
upvoted 1 times
...
Dee83
1 year, 10 months ago
A. Proper security controls, security objectives, and security goals are properly initiated. The security design process within the System Development Life Cycle (SDLC) ensures that proper security controls, security objectives, and security goals are properly initiated. This includes identifying and assessing risks, and implementing controls to mitigate those risks. The security design process is a critical step in ensuring the security and integrity of a system throughout its lifecycle.
upvoted 2 times
jackdryan
1 year, 7 months ago
A is correct
upvoted 1 times
...
...
Billy235
1 year, 11 months ago
Eliminate options B and C as system test and fault mitigation are not security specific and already done somewhere in SDLC. Option D is better than A as it validates security which ends a process. Answer is D.
upvoted 2 times
...
FredDurst
2 years ago
Selected Answer: A
Poorly worded question . The key differentiator here is the term "Objectives" that makes A a winner .
upvoted 1 times
...
rootic
2 years ago
Think it's A.
upvoted 2 times
...
Eltooth
2 years ago
Selected Answer: A
A is correct answer imo.
upvoted 1 times
...
krassko
2 years, 1 month ago
Selected Answer: A
It's A, all others are from "Implementation" phase
upvoted 1 times
...
dev46
2 years, 2 months ago
A & D are "initiated" B & C are "conducted" The secure design process relates to some kind of initiation, so I eliminate B and C A - Aren't security goals and objectives are same? B - but how can validation be part of the process? Thoughts?
upvoted 2 times
...
franbarpro
2 years, 2 months ago
Selected Answer: D
MAAAAAAAAAYYYBBBBEEEEE "D" - Only because it has validation in it. I am thinking as they develop the software they will keep validating and testing the software for bugs and fixing them as the go. https://snyk.io/learn/secure-sdlc/ Implementing SDLC security affects every phase of the software development process. It requires a mindset that is focused on secure delivery, raising issues in the requirements and development phases as they are discovered. This is far more efficient—and much cheaper—than waiting for these security issues to manifest in the deployed application. Secure software development life cycle processes incorporate security as a component of every phase of the SDLC. While building security into every phase of the SDLC is first and foremost a mindset that everyone needs to bring to the table, security considerations and associated tasks will actually vary significantly by SDLC phase.
upvoted 4 times
franbarpro
2 years ago
Changed my answer to "A"
upvoted 1 times
...
...
DERCHEF2009
2 years, 2 months ago
really?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...