CISSP Practice Question: A financial services company is developing a new mobile app. The CTO…
Correct Answer: A. Implement automated security testing within the CI/CD pipeline
Explanation (CISSP Manager Logic):
Integrating security into the development lifecycle (DevSecOps) balances the business need for speed with regulatory compliance requirements. This "shift left" approach allows for continuous verification, ensuring security acts as a business enabler rather than a bottleneck.
By implementing automated security testing, you:
- Enable rapid, competitive deployment cycles through automation.
- Ensure consistent, repeatable compliance with regulatory standards.
- Reduce remediation costs by identifying vulnerabilities early in the lifecycle.
While the other options are relevant, they fall short because:
- B: Delaying deployment creates significant opportunity costs and fails to support business agility.
- C: Prioritizing speed over security introduces unacceptable legal, financial, and reputational risk.
- D: Training is a vital long-term control but does not provide the technical validation required for compliance.
Think like a manager:
Seek solutions that integrate security into existing workflows to achieve both operational velocity and risk mitigation simultaneously.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial