Which approach integrates security into every phase of the development lifecycle?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which approach integrates security into every phase of the development lifecycle?

Security needs to be built in from the start and kept front-and-center throughout design, coding, testing, deployment, and operations. This aligns with DevSecOps/SecDevOps, where security is treated as a shared responsibility and embedded directly into the development pipeline. It emphasizes shifting security left—performing threat modeling, secure coding, and automated vulnerability scanning early and continuously—and integrates security controls and monitoring into CI/CD, infrastructure as code, and runtime operations. That ongoing, holistic approach ensures security isn't an afterthought.

While Agile focuses on iterative delivery and collaboration, it doesn't by itself mandate security across every phase. Waterfall follows a linear path, often pushing security testing to later stages. Versioning manages changes and artifact versions but doesn’t inherently integrate security throughout the lifecycle.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy