nerdexam
(ISC)2

CISSP · Question #1513

Which of the following is the BEST method to identify security controls that should be implemented for a web-based application while in development?

The correct answer is A. Application threat modeling. The best method to identify security controls that should be implemented for a web-based application while in development is application threat modeling. Application threat modeling is a technique that analyzes the design and architecture of an application, identifies the potenti

Submitted by obi.ng· Mar 5, 2026Software Development Security

Question

Which of the following is the BEST method to identify security controls that should be implemented for a web-based application while in development?

Options

  • AApplication threat modeling
  • BSecure software development.
  • CAgile software development
  • DPenetration testing

How the community answered

(40 responses)
  • A
    73% (29)
  • B
    5% (2)
  • C
    15% (6)
  • D
    8% (3)

Explanation

The best method to identify security controls that should be implemented for a web-based application while in development is application threat modeling. Application threat modeling is a technique that analyzes the design and architecture of an application, identifies the potential threats and vulnerabilities, and determines the appropriate security controls and countermeasures to mitigate the risks. Application threat modeling can help to improve the security of an application, by integrating security into the development process, rather than adding it as an afterthought. Application threat modeling can also help to reduce the cost and complexity of security, by addressing the security issues early in the development process, rather than fixing them later in the testing or deployment process. Application threat modeling typically involves the following steps: Define the scope and objectives of the application, such as the features, functions, users, data, and environment. Decompose the application into its components, such as the assets, processes, interfaces, and dependencies. Identify the threats and vulnerabilities that may affect the application, such as the sources, methods, impacts, and likelihoods. Assess the risks and prioritize the security requirements, such as the confidentiality, integrity, availability, and accountability of the application. Define the security controls and countermeasures that can mitigate the risks, such as the policies, procedures, technologies, and standards. Validate and verify the security controls and countermeasures, such as the testing, auditing, and monitoring of the application. Secure software development, agile software development, and penetration testing are not the best methods to identify security controls that should be implemented for a web-based application while in development. These are techniques or methodologies that can help to improve the quality, efficiency, and agility of the software development process, but they do not directly address the security aspects of the application. Secure software development is a process that applies security principles and practices throughout the software development life cycle, such as security planning, analysis, design, implementation, testing, and maintenance. Agile software development is a process that follows an iterative and incremental approach to software development, such as Scrum, Kanban, or Extreme Programming. Penetration testing is a process that simulates an attack on a system or an application, to evaluate its security posture and identify its weaknesses or vulnerabilities.

Topics

#threat modeling#application security#SDLC#security controls

Community Discussion

No community discussion yet for this question.

Full CISSP Practice