nerdexam
CompTIA

CAS-001 · Question #359

The Security Development Lifecycle (SDL) consists of various security practices that are grouped under seven phases. Which of the following security practices are included in the Requirements phase?…

The correct answer is B. Create Quality Gates/Bug Bars D. Security and Privacy Risk Assessment. The Requirements phase of the Security Development Lifecycle (SDL) includes the following security practices: Security and Privacy Requirements Create Quality Gates/Bug Bars Security and Privacy Risk Assessment Answer option C is incorrect. Attack Surface Analysis/Reduction is…

Technical Integration of Enterprise Components

Question

The Security Development Lifecycle (SDL) consists of various security practices that are grouped under seven phases. Which of the following security practices are included in the Requirements phase? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AIncident Response Plan
  • BCreate Quality Gates/Bug Bars
  • CAttack Surface Analysis/Reduction
  • DSecurity and Privacy Risk Assessment

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    94% (29)
  • C
    3% (1)

Explanation

The Requirements phase of the Security Development Lifecycle (SDL) includes the following security practices: Security and Privacy Requirements Create Quality Gates/Bug Bars Security and Privacy Risk Assessment Answer option C is incorrect. Attack Surface Analysis/Reduction is a security practice included in the Design phase of the Security Development Lifecycle (SDL). Answer option A is incorrect. Incident Response Plan is a security practice included in the Release phase of the Security Development Lifecycle (SDL).

Topics

#SDL#security development lifecycle#requirements phase#security practices

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice