Practice Question
Your company is adopting a DevSecOps approach for a new application that handles payment card information. During development, a developer suggests disabling input validation temporarily to accelerate integration testing. What is the BEST response from a security perspective?
A. Allow the change, provided it is reversed before production deployment.
B. Deny the request and enforce secure coding practices at all times.
C. Suggest using synthetic test data and maintain all security controls.
D. Use a separate insecure test environment to allow faster progress.
1
6 comments
Fouad Ahmed
6
Practice Question
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by