8.0 Software Development Security

Secure SDLC Practice Questions

SDLC models, DevSecOps, maturity models, secure coding standards, and software acquisition risk.

One solved question, so you can see how these are marked

A program manager is selecting an SDLC approach for a safety-sensitive system whose requirements are expected to change as prototypes are evaluated. Which approach BEST balances iterative learning with explicit attention to risk?

Spiral, because each iteration includes risk analysis and prototyping before proceeding.

The spiral model uses repeated cycles that include objectives, risk analysis, development, and evaluation, making it suitable when uncertainty and risk are significant. Waterfall is sequential, Agile does not inherently eliminate risk analysis, and DevOps addresses collaboration and delivery rather than replacing the SDLC risk process.

Every question in the set below is marked like this. The answers stay hidden until you pick one.