exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 341 discussion

Actual exam question from Isaca's CISM
Question #: 341
Topic #: 1
[All CISM Questions]

Which of the following is the MOST effective way to help ensure web developers understand the growing severity of web application security risks?

  • A. Standardize secure web development practices
  • B. Integrate security into the early phases of the development life cycle
  • C. Incorporate security requirements into job descriptions
  • D. Implement a tailored security awareness training program
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
e891cd1
8 months ago
b. integrate security into early phases of web development is the most effective way to get them to understand the important. The early phases will let them be proactive developers becoming more aware of potential risks associated with web application development. Although i get giving a tailored training but incorporating security in the earliest dev cycles would be more effective.
upvoted 1 times
...
blehbleh
11 months, 2 weeks ago
Selected Answer: D
I don't know how people are selecting anything besides D. The questions states "MOST effective way to help ensure web developers understand". That would be with tailored training. "WEB DEVELOPERS UNDERSTAND", give them tailored training.
upvoted 2 times
...
iTmarcus
1 year ago
Process vs Education. Option D.
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: D
Effective way to make them understand
upvoted 2 times
...
Nnatech
1 year, 2 months ago
Option D is correct.
upvoted 2 times
...
oluchecpoint
1 year, 3 months ago
Option D
upvoted 2 times
...
AaronS1990
1 year, 3 months ago
Selected Answer: D
I agree with Jaiz. It is talking about helping them "understand" something. This isn't to do with implementing things into the SDLC, this is to do with training
upvoted 2 times
...
richck102
1 year, 6 months ago
D. Implement a tailored security awareness training program
upvoted 2 times
...
wello
1 year, 6 months ago
Selected Answer: D
To make them understand the risk, we need a tailored training.
upvoted 2 times
...
Saisharan
1 year, 6 months ago
Option D, implementing a tailored security awareness training program, directly addresses the need for web developers to understand the growing severity of web application security risks. By providing targeted training, developers can gain knowledge about the specific risks, vulnerabilities, and best practices related to web application security. While integrating security into the development life cycle (Option B) is important for proactive security measures, it may not solely address the need for understanding the severity of risks. - So I would go with Option D.
upvoted 1 times
...
Dravidian
1 year, 8 months ago
Selected Answer: D
I picked Option B as well first. But D does make more sense. The question is talking about most effective way to make them "understand" the risks. Training would it.
upvoted 3 times
...
cheesesteak
1 year, 8 months ago
Selected Answer: B
The MOST effective way to help ensure web developers understand the growing severity of web application security risks is B. Integrate security into the early phases of the development life cycle. Integrating security into the early phases of the development life cycle, also known as "shift left" in the field of software development, involves incorporating security considerations and practices from the very beginning of the development process. This includes activities such as threat modeling, secure coding practices, code reviews, and security testing, among others. By integrating security into the early phases of the development life cycle, web developers are made aware of the security risks associated with web applications and are equipped with the knowledge and tools to address these risks proactively. While options A, C, and D are also important considerations in promoting web application security, integrating security into the early phases of the development life cycle is considered the most effective approach as it emphasizes proactive security practices rather than relying solely on standardized practices, job descriptions, or security awareness training, which may not be as comprehensive or impactful.
upvoted 3 times
...
CarlLimps
1 year, 9 months ago
Selected Answer: D
I like D - Implement a tailored security awareness training program. The reason is because the question mentions wanting the developers to "understand" the growing severity of web app security risks...that means teaching them, growing their knowledge. Putting steps into the SDLC doesn't increase your chance of them growing their understanding. two cents.
upvoted 1 times
...
it_expert_cism
1 year, 9 months ago
D is correct
upvoted 1 times
...
jaiz
1 year, 9 months ago
Selected Answer: D
The key word from the question is “understand” .. and understanding can be obtained from training.
upvoted 3 times
...
N1co_o
1 year, 10 months ago
Selected Answer: D
D is correct i guess
upvoted 1 times
...
Broesweelies
1 year, 11 months ago
Selected Answer: B
The most effective way to help ensure web developers understand the growing severity of web application security risks is to integrate security into the early phases of the development life cycle (option B).
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...