CAS-002 · Question #777
A member of the software development team has requested advice from the security team to implement a new secure lab for testing malware. Which of the following is the NEXT step that the security…
The correct answer is D. Create a proposal and present it to management for approval. Before implementing a new secure malware lab, the security team must obtain management approval through a formal proposal, as this is the required governance step before any resources are committed.
Question
A member of the software development team has requested advice from the security team to implement a new secure lab for testing malware. Which of the following is the NEXT step that the security team should take?
Options
- APurchase new hardware to keep the malware isolated.
- BDevelop a policy to outline what will be required in the secure lab.
- CConstruct a series of VMs to host the malware environment.
- DCreate a proposal and present it to management for approval.
How the community answered
(36 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D89% (32)
Why each option
Before implementing a new secure malware lab, the security team must obtain management approval through a formal proposal, as this is the required governance step before any resources are committed.
Purchasing hardware before receiving management approval commits company resources without authorization, bypassing the required governance and budget approval process.
Developing a policy before obtaining management approval presupposes the project will be approved and wastes effort if the proposal is rejected or scoped differently.
Constructing VMs before presenting a proposal skips the authorization stage and may result in unauthorized use of infrastructure or rework if requirements change.
Creating and presenting a proposal to management is the correct next step because any significant new infrastructure initiative requires formal authorization before resources, budget, or design work are committed. This follows standard change management and project governance principles, ensuring scope, cost, and risk are reviewed at the appropriate level before any technical or procurement work begins.
Concept tested: Change management approval process for new security infrastructure
Topics
Community Discussion
No community discussion yet for this question.