exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 320 discussion

Actual exam question from Isaca's CISM
Question #: 320
Topic #: 1
[All CISM Questions]

To ensure that a new application complies with information security policy, the BEST approach is to:

  • A. perform a vulnerability analysis
  • B. review the security of the application before implementation
  • C. integrate security functionality during the development stage
  • D. periodically audit the security of the application
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AlexJacobson
11 months, 2 weeks ago
Selected Answer: C
Badly written question, as others have stated already...not enough information to choose between B or C. Anyway, I think this question is meant to test you on the SDLC so in that case, you integrate security into it as early as possible (in this case, development phase, although it should be even earlier, in the design phase). So I vote C.
upvoted 2 times
...
jcisco123
1 year ago
Selected Answer: C
The reason it would be C is that it is considered best practice in DevSecOps for building secure applications. B also makes sense but I would prefer C.
upvoted 2 times
...
AaronS1990
1 year, 4 months ago
I'm not sure they give enough context (yet again). If you're about to develop something then C makes the most sense as people have stated. Though software development is taught briefly on the CISM course I've done, it's not an ISM's job. If the question is talking about something being integrated then the answer is B. Implementing things into security systems (and managing the risk that comes with it) is far more in line with an ISM's work
upvoted 2 times
...
Bl1024
1 year, 4 months ago
Why not B?
upvoted 1 times
AaronS1990
1 year, 4 months ago
Good Question. C certainly makes sense but I too like B in the context of the question
upvoted 1 times
...
...
chanke
1 year, 6 months ago
Selected Answer: C
Remember Bake-in-security throughout the SDLC (software development Lifecycle) from the very beginning of it.
upvoted 3 times
...
richck102
1 year, 7 months ago
Selected Answer: C
C. integrate security functionality during the development stage
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...