CISSP Practice Question (Domain 8: Software Development Security / CI-CD Pipeline Controls)
An organization integrates automated security testing into its CI/CD pipeline. Shortly after deployment, build times increase significantly, and developers begin bypassing security checks to meet release deadlines.
Senior management is concerned about both security and delivery velocity.
What should the security lead do FIRST?
A. Disable automated security testing to restore build speed
B. Tune and prioritize security tests based on risk and criticality
C. Enforce strict policy violations and discipline developers
D. Move security testing entirely to post-deployment monitoring
0
7 comments
Vincent Primiani
7
CISSP Practice Question (Domain 8: Software Development Security / CI-CD Pipeline Controls)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by