C706 SECURE SOFTWARE DESIGN & SDLC 100% SOLVED QUESTIONS ALREADY GRADED A+
Define maintenance updating software systems to improve or correct them Define incident response plan the documented steps to follow when system attack or failure occurs What 8 elements should an incident response plan document? - monitoring duties for production software - a definition for incidents; - a contact for incidents; - emergency contact for priority incidents; - a clear escalation chain - software shutdown procedures - attack specific procedures - security docs & references for externally integrated components Define final security review last step of security testing before release Define end user license agreement [a.k.a EULA] A doc establishing use and liabilities end users and the vendor of software systems Define the Microsoft security development lifecycle A method for integrating security planning into standard development process What are the 3 final security review outcomes in a Microsoft security development lifecycle Passed, passed with recommendations, & failed What is a beta version A nearly complete build used to test functionality or security flaws before release what is an archive? A backup copy What 4 factors establish a reasonable timeline for review? - is it mission critical? - amount of privacy data - is the technology sound? - can system resources handle the usage? What is: secure system retirement? specifying how elements of a system are being taken offline, continuing, and how the data is being protected what is the Microsoft SDL Process Template? Integrates w/Visual Studio to track and audit security requirements
Document information
- Uploaded on
- September 3, 2023
- Number of pages
- 2
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers