nerdexam
CompTIA

CAS-001 · Question #48

Which of the following is the MOST secure way to ensure third party applications and introduce only acceptable risk?

The correct answer is A. Line by line code review and simulation; uncovers hidden vulnerabilities and allows for behavior to. When evaluating third-party applications for acceptable risk, a line-by-line code review combined with simulation (A) is the most thorough method because it provides direct, independent inspection of the source code for hidden backdoors, malicious logic, and undisclosed…

Enterprise Security

Question

Which of the following is the MOST secure way to ensure third party applications and introduce only acceptable risk?

Options

  • ALine by line code review and simulation; uncovers hidden vulnerabilities and allows for behavior to
  • BTechnical exchange meetings with the application's vendor; vendors have more in depth knowledge
  • CPilot trial; minimizes the impact to the enterprise while still providing services to enterprise users.
  • DFull deployment with crippled features; allows for large scale testing and observation of the applications

How the community answered

(66 responses)
  • A
    67% (44)
  • B
    17% (11)
  • C
    12% (8)
  • D
    5% (3)

Explanation

When evaluating third-party applications for acceptable risk, a line-by-line code review combined with simulation (A) is the most thorough method because it provides direct, independent inspection of the source code for hidden backdoors, malicious logic, and undisclosed vulnerabilities, and simulation observes actual runtime behavior. Vendor technical exchange meetings (B) rely entirely on the vendor's candor and may not reveal undisclosed defects. A pilot trial (C) reduces enterprise impact but only exposes runtime-observable issues, not hidden code-level vulnerabilities. Full deployment with crippled features (D) introduces the application broadly before risk is adequately assessed. Only code review and simulation gives the security team full, independent visibility.

Topics

#third-party risk#code review#application security#supply chain security

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice