Software Development Security
CISSP · 30 questions
- A county is building a new benefits-enrollment application. Leadership proposes a single security review one week before go-live. What SDLC practice should security advocate instead?
- The city’s internal DevOps team is adopting continuous delivery, while a legacy vendor still delivers waterfall releases for a mainframe tax batch system. How should security engage both?
- A CIO asks whether the municipality’s custom-development practices are immature or advancing. Which approach best answers that question?
- Developers want to push an emergency schema change straight into the production court-records database overnight. What secure-SDLC expectation should govern that change?
- A high-risk rewrite of a court case-management system is starting. Which teaming model best includes security from the outset?
- A city permitting portal went live last quarter, yet new dependency CVEs keep appearing. What Domain 8 practice should continue as part of SDLC sustainment?
- Municipal developers install unofficial IDE plugins and pull unvetted libraries into a tax-assessment build. Beyond source review, what else must security harden?
- An attacker targets the city's CI/CD system that builds and deploys the citizen services portal. Which pipeline protections should the security architect prioritize?
- The county wants stronger software configuration management for its shared code repositories. Which control set best addresses repository security?
- Before promoting custom city code, the AppSec lead wants defects found without executing the program. Which testing approach belongs in the pipeline?
- Security wants to probe a running staging build of the public parks reservation portal the way an external attacker would. Which test fits?
- A municipal fee calculator ships with dozens of open-source packages. Which control specifically finds known-vulnerable third-party components?
- For a complex city case-management application, testers want runtime insight combined with code-level analysis during functional tests. Which approach matches?
- Developers began using unapproved cloud scanners that upload municipal source to third-party tenants. What should leadership do first for tooling governance?
- A sudden configuration change in production broke the city's utility billing API. What software-security control would best support investigation and accountability?
- SAST and SCA flooded the backlog after a civic services scan. How should the team prioritize remediation?
- Leadership asks whether mandatory SAST gates actually improve outcomes for city applications. What should AppSec measure?
- Before promoting the new municipal grants portal to production, what should the release board require?
- Two weeks after launching a new online license renewal feature, how should the city assess software security effectiveness?
- The planning department wants to buy a commercial off-the-shelf permitting package. What should security do before purchase?
- A city analytics team wants to embed an open-source charting library in an internal dashboard. What assessment is required?
- The city adopts a managed enterprise HR module plus third-party add-ons. What risk posture change should leadership recognize?
- IT must choose SaaS, PaaS, or IaaS for a new citizen engagement app. Why does that choice matter for software security?
- Procurement is evaluating a high-risk vendor for a courts case-management platform. Which due-diligence artifacts are proportionate?
- City developers are wiring a new payment callback that builds database queries from raw request fields. What source-level issue must secure coding prevent?
- The city publishes a public API for street-closure data used by third-party apps. Which controls are essential?
- Municipal engineering wants consistent secure coding across teams building internal services. What should leadership adopt?
- The platform team wants security controls to travel with infrastructure and app deployments automatically. Which approach fits?
- Developers use an LLM coding assistant while building a municipal records search service. What oversight is mandatory?
- The city's delivery pipelines block merges that violate secure coding standards, yet emergencies occur. How should exceptions be handled?