nerdexam
(ISC)2

SSCP · Question #1127

From a security standpoint, the product development life cycle consists of which of the following?

The correct answer is F. All of the items listed. A comprehensive security-focused product development life cycle integrates security considerations across all phases, from initial design to final accreditation.

Submitted by rachelw· Apr 18, 2026Systems and Application Security

Question

From a security standpoint, the product development life cycle consists of which of the following?

Options

  • ACode Review
  • BCertification
  • CAccreditation
  • DFunctional Design Review
  • ESystem Test Review
  • FAll of the items listed

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • D
    6% (2)
  • F
    89% (31)

Why each option

A comprehensive security-focused product development life cycle integrates security considerations across all phases, from initial design to final accreditation.

ACode Review

Code review is only one specific activity and does not encompass the entire security product development life cycle, which includes design, testing, and formal approval stages.

BCertification

Certification is a formal process of technical evaluation but does not cover the complete spectrum of security activities during product development, such as design or coding practices.

CAccreditation

Accreditation is a formal management decision to operate a system, which is a post-certification step and doesn't cover the full development lifecycle activities like design or testing.

DFunctional Design Review

Functional design review is an important early-stage security consideration but does not address the security aspects of coding, testing, or formal authorization.

ESystem Test Review

System test review focuses on the testing phase for security but omits crucial security activities that occur during the design, coding, and formal approval stages of product development.

FAll of the items listedCorrect

A secure product development life cycle (SDLC) integrates security activities throughout all phases, meaning elements like functional design review (D) for early security considerations, code review (A) for implementation quality, and system test review (E) for validation are crucial. Additionally, formal processes like certification (B) and accreditation (C) are often part of the security assurance lifecycle for products, ensuring a comprehensive security approach.

Concept tested: Secure Software Development Lifecycle (SSDLC)

Source: https://learn.microsoft.com/en-us/security/engineering/dev-sec-ops

Topics

#Secure Software Development Life Cycle#Application Security#Security Testing#Certification and Accreditation

Community Discussion

No community discussion yet for this question.

Full SSCP Practice