Questions

  1. Does Microsoft SDL stand for Security Development Lifecycle?
  2. According to SDL, what activities should be done during the design stages?
    1. Establishing design requirements
    2. Performing attack surface analysis reduction
    3. User threat modeling
    4. All of the above
  1. In OWASP SAMM, what security practice is not part of security governance
    1. Security and metrics
    2. Education and guidance
    3. Secure architecture
    4. Policy and compliance
  2. In OWASP SAMM, which security practice is not part of security operations?
    1. Issue Management
    2. Security requirements
    3. Environment hardening
    4. Operational enablement
  3. What is not one of the characteristics of the security office under CTO?
    1. Large security team size—over 100 members
    2. No dedicated CSO
    3. The security team ...

Get Hands-On Security in DevOps now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.