A. a JavaScript library only B. a buffer overflow exploit C. a low-level CPU register D. a governance and management framework for enterprise information and technology
Correct Answer: D. a governance and management framework for enterprise information and technology
A. a database diagram notation B. a web browser extension C. U.S. federal information processing standards for approved security and information processing requirements D. a password cracking tool
Correct Answer: C. U.S. federal information processing standards for approved security and information processing requirements
A. a compiler optimization flag B. a file compression format C. a CSS framework D. a risk-based method focused on operationally critical threats, assets and vulnerabilities
Correct Answer: D. a risk-based method focused on operationally critical threats, assets and vulnerabilities
A. a buffer overflow exploit B. a JavaScript library only C. a governance and management framework for enterprise information and technology D. a low-level CPU register
Correct Answer: C. a governance and management framework for enterprise information and technology
A. skipping all testing B. writing code without review C. only increasing screen brightness D. planned activities used to ensure software processes and products meet quality standards
Correct Answer: D. planned activities used to ensure software processes and products meet quality standards
A. building software so confidentiality, integrity and availability are considered from the start B. focusing only on interface colors C. adding security only after deployment D. removing all user authentication
Correct Answer: A. building software so confidentiality, integrity and availability are considered from the start
A. skipping all testing B. writing code without review C. planned activities used to ensure software processes and products meet quality standards D. only increasing screen brightness
Correct Answer: C. planned activities used to ensure software processes and products meet quality standards
A. removing all user authentication B. building software so confidentiality, integrity and availability are considered from the start C. focusing only on interface colors D. adding security only after deployment
Correct Answer: B. building software so confidentiality, integrity and availability are considered from the start
A. writing code without review B. skipping all testing C. only increasing screen brightness D. planned activities used to ensure software processes and products meet quality standards
Correct Answer: D. planned activities used to ensure software processes and products meet quality standards
A. adding security only after deployment B. building software so confidentiality, integrity and availability are considered from the start C. removing all user authentication D. focusing only on interface colors
Correct Answer: B. building software so confidentiality, integrity and availability are considered from the start
A. using no threat modeling B. checking security only after a breach C. integrating security requirements, design, coding, testing and maintenance throughout development D. publishing source code publicly by default
Correct Answer: C. integrating security requirements, design, coding, testing and maintenance throughout development
A. only the logo of the system B. environment, platform, dependencies and operational constraints that can affect security C. only font selection D. only marketing budget
Correct Answer: B. environment, platform, dependencies and operational constraints that can affect security