EXAM VERSION COMPLETE ACCURATE EXAM
QUESTIONS WITH DETAILED VERIFIED
ANSWERS (100% CORRECT ANSWERS)
Within OpenSAMM, what focuses on the processes and activities
related to organizational software development activities within
OpenSAMM practice areas? - ANSWER Governance
Which practice in the Ship (A5) phase of the security development cycle
verifies whether the product meets security mandates? - ANSWER A5
policy compliance analysis
Within OpenSAMM, what focuses on the processes and activities
related to creating software within development projects within
OpenSAMM practice areas? - ANSWER Construction
Which practice in the Ship (A5) phase of the security development
cycle uses tools to identify weaknesses in the product? - ANSWER
Vulnerability scan
Which post-release support activity should be completed when
companies are joining together? - ANSWER Security architectural
reviews
Which of the Ship (A5) deliverables of the security development cycle
are performed with A5 policy compliance analysis? - ANSWER analyze
activities and standards
, Which of the Ship (A5) deliverables of the security development cycle
are performed with code-assisted penetration testing? - ANSWER white-
box security testing
Which of the Ship (A5) deliverables of the security development cycle
are performed with open-source licensing review? - ANSWER license
compliance
Which of the Ship (A5) deliverables of the security development cycle
are performed with final security review? - ANSWER release and ship
Which phase of penetration testing allows for remediation to be
performed? - ANSWER deploy
Which key deliverable occurs during post-release support? - ANSWER
Third-party reviews
Which business function of OpenSAMM is associated with the
following core practices, governance? - ANSWER policy and
compliance
Which business function of OpenSAMM is associated with the
following core practices, construction? - ANSWER threat assessment
Which business function of OpenSAMM is associated with the
following core practices, verification? - ANSWER code review
, Which business function of OpenSAMM is associated with the
following core practices, deployment? - ANSWER vulnerability
management
What should the PIA include? - ANSWER summary of legislation,
required process steps, technologies and techniques, and additional
resources
What is the primary task of the PIA process? - ANSWER to determine
the need in the system, along with an initial definition of the problem to
be solved.
Which practice in the Ship (A5) phase of the security development
cycle verifies whether the product meets security mandates? - ANSWER
A5 policy compliance analysis
Which post-release support activity defines the process to communicate,
identify, and alleviate security threats? - ANSWER PRSA1: External
vulnerability disclosure response
Which post-release support activity defines the process to communicate,
identify, and alleviate security threats? - ANSWER PRSA1: External
vulnerability disclosure response
What are two core practice areas of the OWASP Security Assurance
Maturity Model (OpenSAMM)? - ANSWER Governance, Construction