Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

A Bengaluru fintech is building a mobile payments app. Security architects prepare threat models and define secure coding standards at the start of the project, not after deployment. This approach is best described as:

This is shifting security left in a secure SDLC. Threat modelling and secure coding standards are introduced during early planning and design, so vulnerabilities are prevented rather than fixed later through post-release testing or patches, which lowers cost and risk.

  1. AShifting security left within a secure SDLCCorrect
  2. BPost-release penetration testing
  3. CReactive patch management
  4. DDisaster recovery planning

Explanation

Embedding security activities such as threat modelling and coding standards in the early phases is called shifting left in a secure SDLC. It reduces cost of fixing flaws. Penetration testing and patching are later, reactive controls, and disaster recovery concerns continuity, not development.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions