nerdexam
(ISC)2

CGRC · Question #464

Developmental testing and evaluation is a type of control Assessment and its activities include the following except one. Response:

The correct answer is D. Audits. Developmental testing and evaluation (DT&E) activities include design reviews, various forms of testing, and application scanning, but typically do not encompass formal audits.

Assessment/Audit of Security and Privacy Controls

Question

Developmental testing and evaluation is a type of control Assessment and its activities include the following except one. Response:

Options

  • ADesign and code reviews
  • BRegression testing
  • CApplication scanning
  • DAudits

How the community answered

(45 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    2% (1)
  • D
    87% (39)

Why each option

Developmental testing and evaluation (DT&E) activities include design reviews, various forms of testing, and application scanning, but typically do not encompass formal audits.

ADesign and code reviews

Design and code reviews are integral DT&E activities that identify vulnerabilities and errors early in the software development lifecycle.

BRegression testing

Regression testing is a common DT&E activity performed to ensure that new code or changes do not negatively impact existing functionality or security.

CApplication scanning

Application scanning, including static or dynamic analysis, is a key DT&E activity used to identify security vulnerabilities in software code.

DAuditsCorrect

Audits are typically independent, formal examinations for compliance verification, distinct from developmental testing activities focused on verifying functionality and security during development.

Concept tested: Developmental testing and evaluation activities

Source: https://csrc.nist.gov/glossary/term/developmental_testing_and_evaluation

Topics

#Developmental Testing#Control Assessment Activities#SDLC Security#Auditing

Community Discussion

No community discussion yet for this question.

Full CGRC Practice