nerdexam
Isaca

CGEIT · Question #290

Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified. Which of the

The correct answer is B. Ensure the evaluation process requires independent assessment of solutions prior to. The failure of a critical security feature like RBAC indicates insufficient verification before deployment; independent assessment before rollout is the best preventative measure.

Submitted by marco_it· Apr 18, 2026Governance of Enterprise IT

Question

Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified. Which of the following is the BEST way to prevent reoccurrence in the future?

Options

  • AEnsure supplier contracts include penalties if solutions do not meet functional requirements
  • BEnsure the evaluation process requires independent assessment of solutions prior to
  • CEnsure supplier contracts include a provision for the right to audit on an annual basis
  • DEnsure procurement processes require the identification of alternate vendors to ensure business

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    83% (20)
  • C
    8% (2)
  • D
    4% (1)

Why each option

The failure of a critical security feature like RBAC indicates insufficient verification before deployment; independent assessment before rollout is the best preventative measure.

AEnsure supplier contracts include penalties if solutions do not meet functional requirements

Penalties are reactive measures for non-compliance and do not prevent issues from occurring in the first place.

BEnsure the evaluation process requires independent assessment of solutions prior toCorrect

An independent assessment of solutions prior to rollout, particularly for critical functions like role-based access control (RBAC) handling sensitive data, provides an objective verification that the solution meets all specified functional and security requirements. This proactive testing by a party separate from the development or integration team can identify and remediate defects before they impact production, preventing reoccurrence of such issues after deployment.

CEnsure supplier contracts include a provision for the right to audit on an annual basis

An annual audit is a periodic review; the issue occurred upon rollout, suggesting a need for upfront verification rather than post-deployment auditing.

DEnsure procurement processes require the identification of alternate vendors to ensure business

Identifying alternate vendors is a procurement strategy for business continuity and competition, not a direct measure to prevent functionality errors in a deployed solution.

Concept tested: Software quality assurance, pre-deployment testing

Source: https://learn.microsoft.com/en-us/azure/security/develop/secure-development-lifecycle

Topics

#Security Controls#Quality Assurance#Independent Assessment#Risk Prevention

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice