IsacaIsaca
CISA · Question #449
CISA Question #449: Real Exam Question with Answer & Explanation
Sign in or unlock CISA to reveal the answer and full explanation for question #449. The question stem and answer options stay visible for context.
Submitted by sofia.br· Apr 18, 2026Information Systems Acquisition, Development, and Implementation
Question
An IS auditor is assessing an organization's DevSecOps approach. Which of the following BEST indicates a proactive approach to identifying vulnerabilities?
Options
- AIntegration of automated security testing tools into the continuous integration/continuous delivery
- BOpen-source dependency checks within continuous integration/continuous delivery (CI/CD)
- CUse of the most current development frameworks and libraries
- DPost-implementation vulnerability scans on application deployments
Unlock CISA to see the answer
You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#DevSecOps#Automated Security Testing#CI/CD Security#Vulnerability Identification