C
LO
YC
D
U
ST
D487 SECURE SW DESIGN STUDY
GUIDE
, Which practice in the Ship (A5) phase of the security development cycle verifies whether the
product meets security mandates? - ANS A5 policy compliance analysis
Which post-release support activity defines the process to communicate, identify, and alleviate
security threats? - ANS PRSA1: External vulnerability disclosure response
K
What are two core practice areas of the OWASP Security Assurance Maturity Model
C
(OpenSAMM)? - ANS Governance, Construction
Which practice in the Ship (A5) phase of the security development cycle uses tools to identify
LO
weaknesses in the product? - ANS Vulnerability scan
Which post-release support activity should be completed when companies are joining together?
- ANS Security architectural reviews
Which of the Ship (A5) deliverables of the security development cycle are performed during the
YC
A5 policy compliance analysis? - ANS Analyze activities and standards
Which of the Ship (A5) deliverables of the security development cycle are performed during the
code-assisted penetration testing? - ANS white-box security test
D
Which of the Ship (A5) deliverables of the security development cycle are performed during the
open-source licensing review? - ANS license compliance
U
Which of the Ship (A5) deliverables of the security development cycle are performed during the
final security review? - ANS Release and ship
ST
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on agile? - ANS iterative development
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on devops? - ANS continuous integration and continuous
deployments
How can you establish your own SDL to build security into a process appropriate for your
organization's needs based on cloud? - ANS API invocation processes