nerdexam
CompTIA

CAS-002 · Question #849

A security architect has been engaged during the implementation stage of the SDLC to review a new HR software installation for security gaps. With the project under a tight schedule to meet market…

The correct answer is B. Perform a security risk assessment with recommended solutions to close off high-rated risks E. Determine if the information security standards have been complied with by the project. During the implementation stage of the SDLC under time pressure, a security architect should prioritize activities that give the broadest risk reduction and compliance assurance most efficiently.

Enterprise Security

Question

A security architect has been engaged during the implementation stage of the SDLC to review a new HR software installation for security gaps. With the project under a tight schedule to meet market commitments on project delivery, which of the following security activities should be prioritized by the security architect? (Select TWO).

Options

  • APerform penetration testing over the HR solution to identify technical vulnerabilities
  • BPerform a security risk assessment with recommended solutions to close off high-rated risks
  • CSecure code review of the HR solution to identify security gaps that could be exploited
  • DPerform access control testing to ensure that privileges have been configured correctly
  • EDetermine if the information security standards have been complied with by the project

How the community answered

(39 responses)
  • A
    21% (8)
  • B
    64% (25)
  • C
    5% (2)
  • D
    10% (4)

Why each option

During the implementation stage of the SDLC under time pressure, a security architect should prioritize activities that give the broadest risk reduction and compliance assurance most efficiently.

APerform penetration testing over the HR solution to identify technical vulnerabilities

Penetration testing is resource-intensive and typically performed closer to or after deployment; running it during implementation under a tight schedule would consume time without the product being stable enough for meaningful results.

BPerform a security risk assessment with recommended solutions to close off high-rated risksCorrect

A security risk assessment identifies the highest-rated risks and provides actionable remediation recommendations, giving the team the most impactful security improvements within a tight schedule by focusing effort where it matters most.

CSecure code review of the HR solution to identify security gaps that could be exploited

A secure code review requires significant time and access to source code, making it impractical to prioritize when the project is under a tight delivery schedule during implementation.

DPerform access control testing to ensure that privileges have been configured correctly

Access control testing is a narrowly scoped activity that only addresses privilege configuration and would not provide the broad security coverage needed given the time constraints.

EDetermine if the information security standards have been complied with by the projectCorrect

Verifying compliance with information security standards confirms whether baseline security requirements have been met across the project, providing systematic coverage of security obligations without requiring deep technical testing of every component.

Concept tested: SDLC security activities prioritization under constraints

Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

Topics

#SDLC security#risk assessment#security compliance#security architecture review

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice