Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 92 discussion

Actual exam question from ISC's CISSP
Question #: 92
Topic #: 1
[All CISSP Questions]

A financial organization that works according to agile principles has developed a new application for their external customer base to request a line of credit. A security analyst has been asked to assess the security risk of the minimum viable product (MVP). Which is the MOST important activity the analyst should assess?

  • A. The software has been signed off for release by the product owner.
  • B. The software had been branded according to corporate standards.
  • C. The software has the correct functionality.
  • D. The software has been code reviewed.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
nuggetbutts
2 weeks, 2 days ago
Selected Answer: C
The answer is C becuase of the keywords "financial institution" - in the Financial sector, functionality is tied directly to security.
upvoted 1 times
nuggetbutts
2 weeks, 2 days ago
Changing my answer after more research - it is indeed D. While functionality is tied to security, code review is paramount for financial applications due to high-risk security/regulatory/privacy impacts.
upvoted 1 times
...
...
Ramye
5 months ago
Selected Answer: C
Got to think like an adviser without getting into weeds and providing details solutions.
upvoted 2 times
...
Demo25
1 year, 4 months ago
Selected Answer: D
D. The software has been code reviewed. Code review is a process of inspecting code to identify potential security vulnerabilities. It is an important part of the software development lifecycle, and it can help to prevent security breaches. The other options are not as important as code review. The software has been signed off for release by the product owner: This is important, but it does not guarantee that the software is secure. The software has been branded according to corporate standards: This is also important, but it is not as important as security. The software has the correct functionality: This is important, but it is not as important as security.
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: D
again i forgot to select the answer
upvoted 1 times
...
Bach1968
1 year, 4 months ago
In assessing the security risk of the minimum viable product (MVP) for a financial organization's new application, the most important activity for the security analyst to assess is option D: The software has been code reviewed. Code review is a crucial security practice that helps identify and address security vulnerabilities and weaknesses in the software's code. By conducting a thorough code review, the security analyst can identify potential security flaws, coding errors, and vulnerabilities that could be exploited by attackers. This allows for the identification and mitigation of security risks before the software is released to customers, helping to ensure a higher level of security in the application.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
C. An MVP is not a finished product, but a test: "An MVP allows you to prove a concept before committing too much time or budget to full-blown product development. Most agree that an MVP is a product with a minimal number of features needed to engage customers and validate a basic concept for further development. Importantly, it’s not final — the idea is that it’s something you augment and refine over time." https://thenewstack.io/building-an-minimum-viable-product-a-founders-guide-to-success/ "Minimum Viable Product is not a finished product or version 1.0. It is the smallest part of the product that clearly demonstrates its main functionality and is available to the public. MVP does not have to work, it can be a prototype of a web application explaining the main idea of a product, for example. MVP’s role is to get feedback from the user and learn what he likes about the product and what the things that he does not need are." https://www.scrumdesk.com/what-is-minimum-viable-product/
upvoted 2 times
...
oudmaster
1 year, 11 months ago
Option D is the only answer that is related to the security analyst duty.
upvoted 2 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: D
A minimum viable product (MVP) is a version of a product with just enough features to be usable by early customers who can then provide feedback for future product development and updates / upgrades. The question specially asks about THE SECURITY RISK of the MVP. In other words, we already have an MVP, i.e., correct functionality. What we now want is to evaluate the security around this correctly functioning system, not to evaluate if it functions correctly.
upvoted 4 times
somkiatr
1 year, 11 months ago
Agreed.
upvoted 1 times
...
...
sphenixfire
2 years, 1 month ago
Selected Answer: D
a security analyst in this case is a pentester. it's not the job to check function, branding and especially not this job to accept a sign off of a product owner. so my vote is D
upvoted 2 times
...
niti
2 years, 1 month ago
Selected Answer: C
Keywords in the question: " works according to agile principles" "minimum viable product" so functionality is the main agenda - Ans is "C"
upvoted 1 times
...
niti
2 years, 1 month ago
Keywords in the question: " works according to agile principles" "minimum viable product" so functionality is the main agenda - Ans is "C"
upvoted 1 times
...
franbarpro
2 years, 1 month ago
Selected Answer: D
As a security analyst - You should only care if the code has been reviewed from security standpoint. All the other stuff...... let them deal with it.
upvoted 3 times
...
Ncoa
2 years, 1 month ago
Selected Answer: C
MVP is being able to demonstrate the functionality of the product to the external customer base to ensure it meets requirements and the appetite to complete development
upvoted 1 times
Ncoa
2 years, 1 month ago
Actually I think D is correct from a security risk perspective. My bad
upvoted 1 times
...
...
wyerock
2 years, 2 months ago
Selected Answer: D
A, B, C do not impact security risk
upvoted 2 times
...
stickerbush1970
2 years, 2 months ago
Selected Answer: A
B, C, and D are covered under A.
upvoted 3 times
Mgz156
2 years, 2 months ago
But as a Security Analyst your first job is to check the code. Answer is D
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...