ISC2 CISSP Practice Question

A financial services company is developing a new online banking platform that will handle sensitive customer data and high-value transactions. The lead security architect, wanting to establish a foundational understanding of the platform's security posture early in the SDLC, mandates an analysis to map all user interfaces, APIs, database connections, and third-party services. Which of the following BEST describes the primary purpose of conducting this attack surface analysis?

  • To estimate the time required for subsequent penetration testing activities

  • To identify all potential paths an attacker might use to gain unauthorized access

  • To determine the prioritization sequence for component security testing

  • To calculate the total lines of code in the platform

ISC2 CISSP
Software Development Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot