Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 258 discussion

Actual exam question from ISC's CISSP
Question #: 258
Topic #: 1
[All CISSP Questions]

Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and which of the following?

  • A. Protecting
  • B. Copying
  • C. Enhancing
  • D. Executing
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
SSimko
10 months ago
It is A OWASP Secure Code Review Guide page 23 states the following: Who Should Perform Secure Code ReviewsSome organizations assume secure code review can be a job for a security or risk-analysis team member. How-ever all developers need to understand the exposure points of their applications and what threats exist for theirapplications.Many companies have security teams that do not have members with coding backgrounds, which can makeinteractions with development teams challenging. Because of this development teams are usually skeptical ofsecurity input and guidance. Security teams are usually willing to slow things down to ensure confidentialityand integrity controls are in place while developers are face with pressure from business units they support tocreate and update code as quickly as possible."
upvoted 2 times
...
CoolCat22
11 months, 2 weeks ago
Selected Answer: A
A. Protecting
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
A. Protecting Consistently written and well-documented code makes it easier to review and audit for security vulnerabilities and compliance with security standards and best practices. It helps protect the application against potential security threats and risks.
upvoted 3 times
Soleandheel
11 months, 2 weeks ago
The Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and A. Protecting. A secure SDLC involves integrating security testing and activities into the software development process, ensuring that security is a component of every phase of the SDLC. This includes writing security requirements alongside functional requirements, performing architecture risk analysis during the design phase, and conducting code reviews during coding and building to protect the application code.
upvoted 1 times
...
...
InclusiveSTEAM
1 year, 1 month ago
C is the anwer The Security Software Development Life Cycle (SDLC) expects consistent code to allow ease of auditing and enhancing, option C. Consistent, standardized code makes it easier to maintain, update, modify, and add new functionality to an application over time. This matches enhancing. Protecting, copying, and executing code are not directly enabled by consistent coding. Though protection may be an indirect benefit. A key goal of disciplined secure SDLC processes is to produce uniform code that is straightforward to audit for security and quality while also positioning the application to be enhanced with new features over time. Therefore, enhancing is the secondary goal, along with auditing, that consistent code practices aim to achieve. This makes option C correct.
upvoted 2 times
...
BLADESWIFTKNIFE
1 year, 2 months ago
The Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and enhancing1. This is because writing code consistently helps with code readability, maintainability, and ease of auditing.
upvoted 3 times
...
liebeskind
1 year, 6 months ago
Selected Answer: C
Vote for C. Enhancing. When a new or better programming style / technique / methodology was found, it is easier to search the entire program and change them (Find and replace) if the codes are consistent.
upvoted 2 times
...
DJOEK
1 year, 10 months ago
Selected Answer: A
Security Software Development Life Cycle (SDLC) expects application code to be written in a consistent manner to allow ease of auditing and protecting the integrity of the code, the application, and the data it handles. This includes following a consistent process for code development, testing, and deployment, using secure coding practices and guidelines, and implementing appropriate security controls and monitoring mechanisms. B. Copying, C. Enhancing and D. executing are not the correct answer in this context as the Security Software Development Life Cycle (SDLC) is a process, not an action.
upvoted 2 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
oudmaster
1 year, 11 months ago
Can someone elaborate please and put a reference?
upvoted 4 times
...
Jamati
2 years ago
When the code is consistent, it's easier to understand and test.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...