CISSP Practice Question (Domain 8: Software Development Security)
A product team used an AI coding assistant to build a payment feature and wants it in Friday's release. Nobody threat modeled the code, and the pipeline only runs unit tests. What should the application security manager require FIRST?
A. Static and dynamic scanning gates in the pipeline
B. Threat model of the feature's payment data flows
C. Senior developer review of the generated code
D. Feature flag and rollback plan for the release
(Explain your answer for more points in the comments!)
Come back for the answer tomorrow, or study more now!
0
4 comments
Vincent Primiani
7
CISSP Practice Question (Domain 8: Software Development Security)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by