exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 164 discussion

Actual exam question from CompTIA's CS0-002
Question #: 164
Topic #: 1
[All CS0-002 Questions]

At which of the following phases of the SDLC should security FIRST be involved?

  • A. Design
  • B. Maintenance
  • C. Implementation
  • D. Analysis
  • E. Planning
  • F. Testing
Show Suggested Answer Hide Answer
Suggested Answer: E 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
d8viey
1 year, 6 months ago
Selected Answer: E
Shift-left
upvoted 1 times
...
catastrophie
2 years, 3 months ago
E is always the answer when these types of questions are asked. If you see "At which phase of the *insert type of development or life cycle* should security included, first started, defined, implemented, etc?" The answer is always in the planning and requirements phase. You'll see lots of this within project management questions.
upvoted 4 times
2Fish
2 years, 2 months ago
Agree 100%. Security should be discussed from the beginning. It is everyones responsibility.
upvoted 2 times
...
...
jleonard_ddc
2 years, 4 months ago
Selected Answer: E
Obviously security should ideally be involved at all stages. The SDLC is as follows: Planning Requirements Design Implementation Testing Deployment Maintenance
upvoted 2 times
...
chiquito
2 years, 5 months ago
Selected Answer: D Analysis may be the right answer as per CompTIA Cybersecurity Analyst (CySA+) Study Guide: Exam CS0-002, Second Edition Requirement. Once an effort has been deemed feasible, it will typically go through an analysis and requirements definition phase. In this phase customer input is sought to determine what the desired functionality is, what the current system or application currently does and doesn't do, and what improvements are desired. Requirements may be ranked to determine which are most critical to the success of the project. Tip Security requirements definition is an important part of the analysis and requirements definition phase. It ensures that the application is designed to be secure and that secure coding practices are used.
upvoted 1 times
...
albano23412415
2 years, 5 months ago
Selected Answer: A
ng, a secure SDLC involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.
upvoted 1 times
...
MrRobotJ
2 years, 6 months ago
Selected Answer: E
Which phase of SDLC security is first? Requirement Planning First, you need to plan. While planning may be the most contentious phase of the secure software development life cycle, it's also often the most important. During this phase, you'll determine what your project's security requirements are.
upvoted 2 times
...
R00ted
2 years, 7 months ago
Selected Answer: E
Security requirements definition is an important part of the analysis and requirements definition phase. It ensures that the application is designed to be secure and that secure coding practices are used.
upvoted 2 times
...
choboanon
2 years, 7 months ago
Selected Answer: E
Planning is the first phase and security should be involved from the start.
upvoted 1 times
Whoah
2 years, 6 months ago
Planning is the second phase behind design, according to my reading
upvoted 1 times
...
...
RoVasq3
2 years, 7 months ago
Selected Answer: E
Embedding Security into All Phases of the SDLC Ideally, you should secure each phase of the SDLC in the most appropriate manner for stakeholders present at that stage, while also ensuring that each security measure facilitates security practices across the whole project. Link https://www.aquasec.com/cloud-native-academy/supply-chain-security/secure-software-development-lifecycle-ssdlc/
upvoted 1 times
...
[Removed]
2 years, 7 months ago
Selected Answer: E
I'm going with Planning on this one. Security should be incorporated at every stage. The planning and requirements phase will be where the security requirements are planned out before being incorporated into the design.
upvoted 4 times
...
amateurguy
2 years, 8 months ago
Selected Answer: A
Look at the phases: Phase 1: Requirements. Phase 2: Design. ... Phase 3: Development. ... Phase 4: Verification. ... Phase 5: Maintenance and Evolution. I believe the security person should be involved throughout the whole cycle and since phase 1 (requirements) is not a listed option, we have to with the next option which is Design. So the answer i believe is A. Design. Let me know.
upvoted 3 times
Tag
2 years, 7 months ago
requirement and planning is synonymous in this case E is the answer, you had the right thought lol
upvoted 2 times
...
...
marc4354345
2 years, 8 months ago
security must be adressed already at analysis stage.
upvoted 1 times
marc4354345
2 years, 5 months ago
E makes most sense. Planning.
upvoted 2 times
...
...
Adrian831
2 years, 8 months ago
Selected Answer: A
A sounds good.
upvoted 1 times
Adrian831
2 years, 7 months ago
Changing my answer to E. Planning
upvoted 1 times
...
...
adamhoms
2 years, 8 months ago
Generally speaking, a secure SDLC involves integrating security testing and other activities into an existing development process. Examples include writing security requirements alongside functional requirements and performing an architecture risk analysis during the design phase of the SDLC.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...