nerdexam
Isaca

CISA · Question #597

What type of control has been implemented when secure code reviews are conducted as part of a deployment program?

The correct answer is A. Detective. Secure code reviews identify security flaws or vulnerabilities in code before deployment. This makes them detective controls, since they help find issues but do not directly prevent or correct Option A: Correct - they detect flaws. Option B: Corrective controls are applied…

Submitted by chen.hong· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

What type of control has been implemented when secure code reviews are conducted as part of a deployment program?

Options

  • ADetective
  • BCorrective
  • CMonitoring
  • DDeterrent

How the community answered

(46 responses)
  • A
    87% (40)
  • B
    2% (1)
  • C
    9% (4)
  • D
    2% (1)

Explanation

Secure code reviews identify security flaws or vulnerabilities in code before deployment. This makes them detective controls, since they help find issues but do not directly prevent or correct Option A: Correct - they detect flaws. Option B: Corrective controls are applied after issues are detected. Option C: Monitoring is ongoing observation, not review-based. Option D: Deterrent controls discourage actions (e.g., policies, warnings), not detect issues.

Topics

#Control types#Detective controls#Secure code review#Application security

Community Discussion

No community discussion yet for this question.

Full CISA Practice