Question 16

The Chief Information Security Officer (CISO) has recommended contracting with external experts to perform annual reviews of the enterprise's software products, including penetration testing.
Which post-release deliverable is being described?
  • Question 17

    What is an advantage of using the Agile development methodology?
  • Question 18

    Which software control test examines an application from a user perspective by providing a wide variety of input scenarios and inspecting the output?
  • Question 19

    While performing functional testing of the new product from a shared machine, a QA analyst closed their browser window but did not logout of the application. A different QA analyst accessed the application an hour later and was not prompted to login. They then noticed the previous analyst was still logged into the application.
    How should existing security controls be adjusted to prevent this in the future?
  • Question 20

    Which type of security analysis is performed by injecting malformed data into open interfaces of an executable or running application and is most commonly executed during the testing or deployment phases of the SDLC?