nerdexam
CompTIA

SY0-301 · Question #136

Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following should Pete do NEXT?

The correct answer is B. Tell the application development manager to code the application to adhere to the company's password policy. When a development team plans to violate an existing security policy, the security analyst's immediate responsibility is to direct them to comply with that policy through the appropriate manager. Escalation or policy changes are premature before attempting direct enforcement.

Security program management and oversight

Question

Pete, a security analyst, has been informed that the development team has plans to develop an application which does not meet the company's password policy. Which of the following should Pete do NEXT?

Options

  • AContact the Chief Information Officer and ask them to change the company password policy so that
  • BTell the application development manager to code the application to adhere to the company's password policy.
  • CAsk the application development manager to submit a risk acceptance memo so that the issue can be
  • DInform the Chief Information Officer of non-adherence to the security policy so that the developers can

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    85% (34)
  • C
    10% (4)
  • D
    3% (1)

Why each option

When a development team plans to violate an existing security policy, the security analyst's immediate responsibility is to direct them to comply with that policy through the appropriate manager. Escalation or policy changes are premature before attempting direct enforcement.

AContact the Chief Information Officer and ask them to change the company password policy so that

Changing the company password policy to accommodate non-compliant development undermines the purpose of the policy and is not the security analyst's role or the appropriate first response.

BTell the application development manager to code the application to adhere to the company's password policy.Correct

The security analyst's primary duty is to enforce existing security policy, and the correct next step is to inform the application development manager directly so the application is coded to meet the company's password policy requirements. This is the most direct and appropriate response before considering escalation or policy exceptions.

CAsk the application development manager to submit a risk acceptance memo so that the issue can be

Requesting a risk acceptance memo is appropriate only after exhausting enforcement options - asking for a formal exception before directing the team to comply skips the enforcement step.

DInform the Chief Information Officer of non-adherence to the security policy so that the developers can

Escalating immediately to the CIO bypasses the direct communication channel with the development manager, which should be the first corrective action taken by the analyst.

Concept tested: Security policy enforcement and analyst responsibilities

Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-security-policy

Topics

#password policy#security policy enforcement#compliance#application development

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice