<< Prev Question Next Question >>

Question 66/131

During which stage of the software development life cycle (SDLC) should application security controls FIRST be addressed?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (131q)
Question 1: What is the PRIMARY benefit of effective configuration manag...
Question 2: Which of the following would BEST help to ensure an organiza...
Question 3: Which of the following is the BEST way for an organization t...
Question 4: Which of the following information BEST supports risk manage...
Question 5: The business advantage of implementing authentication tokens...
Question 6: A legacy application does not comply with new regulatory req...
Question 7: In a multinational organization, local security regulations ...
Question 8: An organization has established a bring your own device (BYO...
Question 9: Which of the following processes can be used to remediate id...
Question 10: A risk was identified during a risk assessment. The business...
Question 11: An organization wants to integrate information security into...
Question 12: A financial company executive is concerned about recently in...
Question 13: An information security manager has identified the organizat...
Question 14: What is the PRIMARY purpose of an unannounced disaster recov...
Question 15: Which of the following is the BEST way for an information se...
Question 16: During which of the following development phases is it MOST ...
Question 17: Over the last year, an information security manager has perf...
Question 18: Which of the following is the MOST important security consid...
Question 19: Which of the following should be the PRIMARY driver for sele...
Question 20: Which of the following would BEST enable effective decision-...
Question 21: An information security manager wants to improve the ability...
Question 22: The PRIMARY goal of a post-incident review should be to:...
Question 23: An organization's security policy is to disable access to US...
Question 24: Which of the following is the PRIMARY objective of a busines...
Question 25: Which of the following roles is BEST suited to validate user...
Question 26: An organization has implemented a new security control in re...
Question 27: Which of the following analyses will BEST identify the exter...
Question 28: Which of the following BEST indicates an effective vulnerabi...
Question 29: Which of the following is MOST likely to be a component of a...
Question 30: Which of the following would MOST effectively communicate th...
Question 31: When scoping a risk assessment, assets need to be classified...
Question 32: Who should an information security manager contact FIRST upo...
Question 33: An organization is concerned with the potential for exploita...
Question 34: The BEST way to avoid session hijacking is to use:...
Question 35: Which of the following is the MOST effective approach for de...
Question 36: Which of the following is the BEST way to evaluate the impac...
Question 37: Which of the following provides the MOST comprehensive infor...
Question 38: Which of the following would be MOST helpful when determinin...
Question 39: Which of the following is the MOST important consideration w...
Question 40: Which of the following BEST prepares a computer incident res...
Question 41: Which of the following would be an information security mana...
Question 42: Who should determine data access requirements for an applica...
Question 43: For an organization that is experiencing outages due to mali...
Question 44: Which of the following is MOST important to include in an in...
Question 45: The authorization to transfer the handling of an internal se...
1 commentQuestion 46: Mitigating technology risks to acceptable levels should be b...
Question 47: Which of the following is the MOST effective approach to ens...
Question 48: When establishing escalation processes for an organization's...
Question 49: Which of the following is the MOST important consideration i...
Question 50: Which of the following is an information security manager's ...
Question 51: An, organization's senior management is encouraging employee...
Question 52: Which is the MOST important requirement when establishing a ...
Question 53: A critical vulnerability is found on a server hosting multip...
Question 54: An organization's operations have been significantly impacte...
Question 55: After a server has been attacked, which of the following is ...
Question 56: Which of the following clauses would represent the MOST sign...
Question 57: Which of the following is the BEST strategy to implement an ...
Question 58: The MOST important objective of security awareness training ...
Question 59: Which of the following is MOST important for an information ...
Question 60: Recovery time objectives (RTOs) are an output of which of th...
Question 61: To inform a risk treatment decision, which of the following ...
Question 62: Senior management wants to provide mobile devices to its sal...
Question 63: Which of the following is PRIMARILY influenced by a business...
Question 64: Which of the following is the GREATEST benefit of integratin...
Question 65: Which of the following should be the MOST important consider...
Question 66: During which stage of the software development life cycle (S...
Question 67: An organization finds unauthorized software has been install...
Question 68: When defining and communicating roles and responsibilities b...
Question 69: Which of the following is the BEST course of action if the b...
Question 70: The PRIMARY goal of the eradication phase in an incident res...
1 commentQuestion 71: Which of the following is the BEST method to protect consume...
Question 72: If an organization does not have an information security gov...
Question 73: Which of the following BEST protects against phishing attack...
Question 74: Which of the following is the MOST important consideration w...
Question 75: Which of the following is the MOST important element in the ...
Question 76: Human resources (HR) is evaluating potential Software as a S...
Question 77: Which of the following is the MOST important requirement for...
Question 78: An organization that uses external cloud services extensivel...
Question 79: Which of the following is the MOST important step when estab...
Question 80: In a cloud technology environment, which of the following wo...
Question 81: What is the PRIMARY objective of implementing standard secur...
Question 82: Which of the following is the MOST essential element of an i...
Question 83: Threat and vulnerability assessments are important PRIMARILY...
Question 84: When implementing a security policy for an organization hand...
Question 85: Which of the following is the MAIN benefit of performing an ...
Question 86: Management has announced the acquisition of a new company. T...
Question 87: Which of the following is MOST important to the successful i...
Question 88: Which of the following provides the MOST useful information ...
Question 89: Which of the following provides the MOST essential input for...
Question 90: The MAIN purpose of documenting information security guideli...
Question 91: Labeling information according to its security classificatio...
Question 92: Which of the following would be MOST useful to help senior m...
Question 93: An information security manager has identified that security...
Question 94: Which of the following should be the PRIMARY consideration w...
Question 95: The security baselines of an organization should be based on...
Question 96: The PRIMARY purpose of establishing an information security ...
Question 97: Which of the following is MOST important when selecting an i...
Question 98: Which of the following is MOST effective in reducing the fin...
Question 99: An intrusion has been detected and contained. Which of the f...
Question 100: Which of the following provides the MOST relevant informatio...
Question 101: A security review identifies that confidential information o...
Question 102: Which of the following should an information security manage...
Question 103: Recovery time objectives (RTOs) are BEST determined by...
Question 104: Which of the following would provide the MOST value to senio...
Question 105: Which of the following is MOST important to ensure when an o...
Question 106: Which of the following is the MOST important output from a p...
Question 107: An information security manager wants to document requiremen...
Question 108: Which of the following is the MOST effective method of deter...
Question 109: Which of the following would provide the BEST evidence to se...
Question 110: The MOST important reason to use a centralized mechanism to ...
Question 111: Which of the following is the MOST effective way to address ...
Question 112: Which of the following is the PRIMARY benefit of implementin...
Question 113: An organization implemented a number of technical and admini...
Question 114: Which of the following would be the GREATEST threat posed by...
Question 115: Which of the following is the BEST method for determining wh...
Question 116: Which of the following is MOST important for an information ...
Question 117: During the response to a serious security breach, who is the...
Question 118: For an enterprise implementing a bring your own device (BYOD...
Question 119: The PRIMARY advantage of single sign-on (SSO) is that it wil...
Question 120: The information security manager of a multinational organiza...
Question 121: Which of the following external entities would provide the B...
Question 122: What is the BEST way for an information security manager to ...
Question 123: Which of the following is MOST important to include in a con...
Question 124: Which of the following would be the MOST effective counterme...
Question 125: Which of the following would provide the HIGHEST level of co...
Question 126: A measure of the effectiveness of the incident response capa...
Question 127: Which of the following BEST enables effective information se...
Question 128: When designing security controls, it is MOST important to:...
Question 129: Which of the following is the MOST important reason to invol...
Question 130: It is MOST important for an information security manager to ...
Question 131: The MOST important reason for an information security manage...