nerdexam
CompTIA

CAS-002 · Question #695

A company has decided to use the SDLC for the creation and production of a new information system. The security administrator is training all users on how to protect company information while using…

The correct answer is B. Implementation. This question tests knowledge of which SDLC phase includes user security training and formal management approval before a system goes live.

Technical Integration of Enterprise Components

Question

A company has decided to use the SDLC for the creation and production of a new information system. The security administrator is training all users on how to protect company information while using the new system, along with being able to recognize social engineering attacks. Senior Management must also formally approve of the system prior to it going live. In which of the following phases would these security controls take place?

Options

  • AOperations and Maintenance
  • BImplementation
  • CAcquisition and Development
  • DInitiation

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    91% (42)
  • C
    2% (1)
  • D
    2% (1)

Why each option

This question tests knowledge of which SDLC phase includes user security training and formal management approval before a system goes live.

AOperations and Maintenance

Operations and Maintenance occurs after the system is already live, so training and pre-launch approvals would be too late in this phase.

BImplementationCorrect

The Implementation phase of the SDLC is when the system is being deployed and made operational, making it the appropriate time to conduct user security awareness training and obtain formal management authorization before go-live. Security controls such as training users on social engineering and requiring senior management sign-off are hallmarks of the Implementation phase's acceptance and accreditation activities. This phase bridges development and live operation, so all preparatory human and administrative controls are finalized here.

CAcquisition and Development

Acquisition and Development focuses on designing, purchasing, and building the system, not on user training or formal management authorization for go-live.

DInitiation

Initiation is the earliest SDLC phase concerned with defining the system's purpose and scope, long before training or approval activities are relevant.

Concept tested: SDLC Implementation phase security controls

Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

Topics

#SDLC#implementation phase#security training#management approval

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice