ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During the design phase of a new payroll application, the project team wants to ensure security is properly integrated. Which of the following actions aligns best with the responsibilities of the design phase rather than activities reserved for later SDLC stages?
Conduct a penetration test against the pre-production environment.
Approve the information system for operational use after reviewing residual risk.
Execute code-level static analysis on completed application modules.
Develop a detailed security architecture that defines trust boundaries, data flows, and required controls.
The design phase focuses on translating security requirements into an overall architecture. Creating detailed security architecture diagrams that map trust boundaries, expected data flows, and the controls that must be built into each component is a design-phase task. Code-level static analysis, penetration testing, and formal authorization decisions occur in the development, test, and deployment/operations stages, respectively, after the design has been completed and implemented.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is meant by 'trust boundaries' in security architecture?
Open an interactive chat with Bash
How do data flow diagrams help in the design phase?
Open an interactive chat with Bash
What is the role of required controls in a security architecture?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .