CAS-002 · Question #849
A security architect has been engaged during the implementation stage of the SDLC to review a new HR software installation for security gaps. With the project under a tight schedule to meet market…
The correct answer is B. Perform a security risk assessment with recommended solutions to close off high-rated risks E. Determine if the information security standards have been complied with by the project. During the implementation stage of the SDLC under time pressure, a security architect should prioritize activities that give the broadest risk reduction and compliance assurance most efficiently.
Question
A security architect has been engaged during the implementation stage of the SDLC to review a new HR software installation for security gaps. With the project under a tight schedule to meet market commitments on project delivery, which of the following security activities should be prioritized by the security architect? (Select TWO).
Options
- APerform penetration testing over the HR solution to identify technical vulnerabilities
- BPerform a security risk assessment with recommended solutions to close off high-rated risks
- CSecure code review of the HR solution to identify security gaps that could be exploited
- DPerform access control testing to ensure that privileges have been configured correctly
- EDetermine if the information security standards have been complied with by the project
How the community answered
(39 responses)- A21% (8)
- B64% (25)
- C5% (2)
- D10% (4)
Why each option
During the implementation stage of the SDLC under time pressure, a security architect should prioritize activities that give the broadest risk reduction and compliance assurance most efficiently.
Penetration testing is resource-intensive and typically performed closer to or after deployment; running it during implementation under a tight schedule would consume time without the product being stable enough for meaningful results.
A security risk assessment identifies the highest-rated risks and provides actionable remediation recommendations, giving the team the most impactful security improvements within a tight schedule by focusing effort where it matters most.
A secure code review requires significant time and access to source code, making it impractical to prioritize when the project is under a tight delivery schedule during implementation.
Access control testing is a narrowly scoped activity that only addresses privilege configuration and would not provide the broad security coverage needed given the time constraints.
Verifying compliance with information security standards confirms whether baseline security requirements have been met across the project, providing systematic coverage of security obligations without requiring deep technical testing of every component.
Concept tested: SDLC security activities prioritization under constraints
Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.