PSM-I · Question #17
What are two good ways for a Scrum Team to ensure security concerns are satisfied? (Choose two.)
The correct answer is B. Add security concerns to the definition of "Done". E. Have the Scrum Team create Product Backlog items for each concern. Adding security concerns to the Definition of Done (B) ensures every increment is evaluated against security criteria before being considered complete-this embeds security into the regular workflow. Creating Product Backlog items for each security concern (E) makes security…
Question
What are two good ways for a Scrum Team to ensure security concerns are satisfied? (Choose two.)
Options
- APostpone the work until a specialist can perform a security audit and create a list of security-
- BAdd security concerns to the definition of "Done".
- CAdd a Sprint to specifically resolve all security concerns.
- DDelegate the work to the concerned department.
- EHave the Scrum Team create Product Backlog items for each concern.
How the community answered
(47 responses)- A2% (1)
- B77% (36)
- C13% (6)
- D9% (4)
Explanation
Adding security concerns to the Definition of Done (B) ensures every increment is evaluated against security criteria before being considered complete-this embeds security into the regular workflow. Creating Product Backlog items for each security concern (E) makes security work visible, prioritizable, and trackable like any other work. Postponing for an audit (A) defers risk and creates technical debt. Adding a dedicated security Sprint (C) violates Scrum's principle that each Sprint should deliver a potentially releasable increment-security shouldn't be bolted on. Delegating to another department (D) removes team ownership of quality.
Topics
Community Discussion
No community discussion yet for this question.