exam questions

Exam SY0-501 All Questions

View all questions & answers for the SY0-501 exam

Exam SY0-501 topic 1 question 201 discussion

Actual exam question from CompTIA's SY0-501
Question #: 201
Topic #: 1
[All SY0-501 Questions]

A security analyst has been asked to perform a review of an organization's software development lifecycle. The analyst reports that the lifecycle does not contain a phase in which team members evaluate and provide critical feedback of another developer's code.
Which of the following assessment techniques is BEST described in the analyst's report?

  • A. Architecture evaluation
  • B. Baseline reporting
  • C. Whitebox testing
  • D. Peer review
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Qabil
Highly Voted 5 years, 1 month ago
Peer review is a process used for checking the work performed by one's equals (peers) to ensure it meets specific criteria. Peer review is used in working groups for many professional occupations because it is thought that peers can identify each other's errors quickly and easily, speeding up the time that it takes for mistakes to be identified and corrected. In software development, peer review is sometimes used in code development where a team of coders will have a meeting and go through code line by line (even read it aloud possibly) to look for errors
upvoted 10 times
...
russtest
Most Recent 3 years, 10 months ago
IM confused the analyst reports that the lifecycle DOES NOT contain a phase in which team members evaluate and provide critical feedback of another developer's code. if Peer review could be a team of coders then are they not team members. The question said does not contain in which team members evaluate and provide critical feedback of another developer's code. that sounds like peer review, or unless this question is worded very wrong SMH
upvoted 1 times
...
Dion79
4 years, 1 month ago
Human analysis of software source code is described as a code review or as a manual peer review. It is important that the code be reviewed by developers (peers) other than the original coders to try to identify oversights, mistaken assumptions, or a lack of knowledge or experience. It is important to establish a collaborative environment in which reviews can take place effectively.
upvoted 1 times
...
who__cares123456789___
4 years, 4 months ago
Keyword "peer"...all scientific publications are "peer reviewed" so science "garbage" is NOT published...software need same "peer review" process cause we all know garbageIN=garbageOUT.
upvoted 1 times
...
who__cares123456789___
4 years, 4 months ago
Keyword "peer"...all scientific publications are "peer reviewed" so science "garbage" is published...software need same "peer review" process cause we all know garbageIN=garbageOUT.
upvoted 1 times
lapejor
4 years, 3 months ago
why not white box? if it is a peer he will get access to the code? and none of the Comptia Sec books that I have talks about peer review
upvoted 1 times
...
...
Timileyin
5 years, 1 month ago
Can someone explain why is D please?
upvoted 1 times
Jasonbelt
4 years, 10 months ago
The analyst clearly states that no other developers checked the code, meaning they need their fellow developers, or peers, to check.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago