nerdexam
(ISC)2

CSSLP · Question #142

Which of the following security controls will you use for the deployment phase of the SDLC to build secure software? Each correct answer represents a complete solution. Choose all that apply.

The correct answer is B. Security Certification and Accreditation (C&A) C. Vulnerability Assessment and Penetration Testing D. Risk Adjustments. Key security controls for the deployment phase of the SDLC to build secure software include Security Certification and Accreditation, Vulnerability Assessment and Penetration Testing, and Risk Adjustments.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following security controls will you use for the deployment phase of the SDLC to build secure software? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AChange and Configuration Control
  • BSecurity Certification and Accreditation (C&A)
  • CVulnerability Assessment and Penetration Testing
  • DRisk Adjustments

How the community answered

(27 responses)
  • A
    22% (6)
  • B
    78% (21)

Why each option

Key security controls for the deployment phase of the SDLC to build secure software include Security Certification and Accreditation, Vulnerability Assessment and Penetration Testing, and Risk Adjustments.

AChange and Configuration Control

Change and Configuration Control is primarily an ongoing process throughout the entire SDLC, managing changes to code and infrastructure, rather than a specific control applied solely during the deployment phase for building secure software.

BSecurity Certification and Accreditation (C&A)Correct

Security Certification and Accreditation (C&A) is crucial during deployment as it formally assesses and authorizes the system to operate, considering its security posture prior to going live. This process ensures the system meets defined security requirements and the risks are acceptable.

CVulnerability Assessment and Penetration TestingCorrect

Vulnerability Assessment and Penetration Testing (VAPT) are essential right before or during deployment to identify and remediate any last-minute security flaws or misconfigurations. This helps ensure the deployed system is robust against known attack vectors.

DRisk AdjustmentsCorrect

Risk Adjustments involve reviewing and updating risk assessments based on the actual implementation and testing results during deployment. This ensures that the residual risks are understood and managed, and any necessary mitigating actions are taken before full operational status.

Concept tested: SDLC Deployment phase security controls

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-64rev2.pdf

Topics

#SDLC Deployment#Security Controls#Certification & Accreditation#Vulnerability Assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice