nerdexam
Isaca

CISA · Question #518

An IS auditor is reviewing an organization's transition to DevSecOps. Which of the following is the BEST indication that security is integrated throughout the software development life cycle?

The correct answer is B. Automated security testing is incorporated into the continuous integration/continuous deployment. Integrating automated security testing into the CI/CD pipeline ensures that security checks occur continuously throughout the development life cycle. This demonstrates that security is embedded into the DevSecOps process, enabling early detection and remediation of…

Submitted by satoshi_tk· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

An IS auditor is reviewing an organization's transition to DevSecOps. Which of the following is the BEST indication that security is integrated throughout the software development life cycle?

Options

  • AThe frequency of security-related code releases to the production environment aligns with
  • BAutomated security testing is incorporated into the continuous integration/continuous deployment
  • CThe roles, responsibilities, and accountabilities for secure application development are
  • DTools used for security testing and version control in the development process are highly

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    84% (26)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Integrating automated security testing into the CI/CD pipeline ensures that security checks occur continuously throughout the development life cycle. This demonstrates that security is embedded into the DevSecOps process, enabling early detection and remediation of vulnerabilities before

Topics

#DevSecOps#SDLC Security#Automated Security Testing#CI/CD

Community Discussion

No community discussion yet for this question.

Full CISA Practice