E is always the answer when these types of questions are asked. If you see "At which phase of the *insert type of development or life cycle* should security included, first started, defined, implemented, etc?" The answer is always in the planning and requirements phase. You'll see lots of this within project management questions.
Obviously security should ideally be involved at all stages. The SDLC is as follows:
Planning
Requirements
Design
Implementation
Testing
Deployment
Maintenance
Selected Answer: D
Analysis may be the right answer as per CompTIA Cybersecurity Analyst (CySA+) Study Guide: Exam CS0-002, Second Edition
Requirement. Once an effort has been deemed feasible, it will typically go through an analysis and requirements definition phase. In this phase customer input is sought to determine what the desired functionality is, what the current system or application currently does and doesn't do, and what improvements are desired. Requirements may be ranked to determine which are most critical to the success of the project.
Tip
Security requirements definition is an important part of the analysis and requirements definition phase. It ensures that the application is designed to be secure and that secure coding practices are used.
ng, a secure SDLC involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.
Which phase of SDLC security is first?
Requirement Planning
First, you need to plan. While planning may be the most contentious phase of the secure software development life cycle, it's also often the most important. During this phase, you'll determine what your project's security requirements are.
Security requirements definition is an important part of the analysis and requirements definition phase. It ensures that the application is designed to be secure and that secure coding practices are used.
Embedding Security into All Phases of the SDLC
Ideally, you should secure each phase of the SDLC in the most appropriate manner for stakeholders present at that stage, while also ensuring that each security measure facilitates security practices across the whole project. Link https://www.aquasec.com/cloud-native-academy/supply-chain-security/secure-software-development-lifecycle-ssdlc/
I'm going with Planning on this one.
Security should be incorporated at every stage. The planning and requirements phase will be where the security requirements are planned out before being incorporated into the design.
Look at the phases:
Phase 1: Requirements.
Phase 2: Design. ...
Phase 3: Development. ...
Phase 4: Verification. ...
Phase 5: Maintenance and Evolution.
I believe the security person should be involved throughout the whole cycle and since phase 1 (requirements) is not a listed option, we have to with the next option which is Design.
So the answer i believe is A. Design.
Let me know.
Generally speaking, a secure SDLC involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CS0-002 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
d8viey
1 year, 6 months agocatastrophie
2 years, 3 months ago2Fish
2 years, 2 months agojleonard_ddc
2 years, 4 months agochiquito
2 years, 5 months agoalbano23412415
2 years, 5 months agoMrRobotJ
2 years, 6 months agoR00ted
2 years, 7 months agochoboanon
2 years, 7 months agoWhoah
2 years, 6 months agoRoVasq3
2 years, 7 months ago[Removed]
2 years, 7 months agoamateurguy
2 years, 8 months agoTag
2 years, 7 months agomarc4354345
2 years, 8 months agomarc4354345
2 years, 5 months agoAdrian831
2 years, 8 months agoAdrian831
2 years, 7 months agoadamhoms
2 years, 8 months ago