Q: 20
An analysis of an organization s security breach is complete. The results indicate that the quality of
the code used for updates to its primary customer-facing software has been declining and security
flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
Options
Discussion
I see why people want to pick C, but B is the better fit here.
Pretty sure B, not C. People pick C a lot but that's looking at individuals, not fixing the big picture process. Reviewing the change management control framework gets to the root cause based on exam reports.
Not really D here. B is the better choice, since reviewing the change management control framework hits the root of code quality and security flaws.
Its B
Why wouldn't C be first here, since developer mistakes caused the flaws? Isn't B more about preventing issues at the process level?
B is right for this. The issue's more about process controls than individual dev skills. Someone disagree?
Its D. Not totally sure but policy comes before training or budgets right?
Be respectful. No spam.
Question 20 of 35