ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a sprint retrospective, an Agile development team wants to strengthen its DevSecOps posture. Which action best supports the goal of embedding security into the iterative cycle while matching the intended purpose of the retrospective?
Review security incidents from the sprint and add related security acceptance criteria to the team's Definition of Done for future work
Execute a full dynamic application security test (DAST) against the current build to find undiscovered vulnerabilities
Select a developer to act as security champion and require that person to attend all upcoming daily stand-ups
Reorder the product backlog so security epics are implemented before any new business features
A sprint retrospective is meant to reflect on the just-completed sprint and agree on process improvements for the next one. Discussing any security issues encountered (for example, newly discovered vulnerabilities, policy violations, or tooling gaps) and then updating the team's Definition of Done or working agreements adds concrete security requirements to future work. This turns lessons learned into actionable changes that will be applied in every subsequent iteration. Reprioritizing the backlog is typically handled in backlog refinement or sprint planning, not the retrospective. Executing DAST is a testing activity performed during the sprint, not a process-improvement discussion. Naming a security champion is beneficial but belongs in team-formation or planning ceremonies rather than a retrospective focused on reflecting and adapting processes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a sprint retrospective?
Open an interactive chat with Bash
What is the Definition of Done in Agile?
Open an interactive chat with Bash
How does DevSecOps strengthen security in Agile workflows?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .