ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your project has moved from design into coding, and developers are writing new application modules. To embed security controls during the Development phase of the SDLC, which activity should you prioritize before the code is compiled or executed?
Perform a post-implementation review of system audit logs to confirm security-relevant events were recorded.
Develop and approve the media sanitization and disposal plan for components reaching end-of-life.
Submit the system package to the Authorizing Official to obtain a formal Authorization to Operate (ATO).
Run static application security testing tools against the new source code to detect insecure constructs early.
During the Development (coding) phase, the emphasis is on writing secure code and detecting vulnerabilities as early as possible. Static Application Security Testing (SAST) examines source code or byte-code without running it, allowing security flaws such as injection, insecure API use, or buffer overflows to be found and corrected while the code is still being written. Activities such as post-implementation log reviews occur in the operations phase, retirement planning belongs to the disposal phase, and obtaining an Authorization to Operate is part of the authorization step that follows assessment. Therefore, running SAST (or comparable static code analysis) is the most appropriate security activity to integrate in the development phase.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Static Application Security Testing (SAST)?
Open an interactive chat with Bash
Why is SAST prioritized during the development phase of the SDLC?
Open an interactive chat with Bash
How is SAST different from Dynamic Application Security Testing (DAST)?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .