CompTIA Project+ (PK0-005)Basics of IT and GovernanceEasy

A project involves developing a new online banking application. During the design phase, the security team emphasizes incorporating security measures from the very beginning of the software development lifecycle, rather than adding them as an afterthought. This approach is known as:

  1. AVulnerability Scanning
  2. BSecurity by Obscurity
  3. CSecurity by Design
  4. DPenetration Testing
Show answer & explanation

Correct answer: C. Security by Design

Security by Design is an approach that integrates security considerations into every phase of the development lifecycle, from initial design to deployment and maintenance, rather than bolting them on at the end.

Why the other options are wrong

  • A. Vulnerability scanning automatically identifies known weaknesses, often performed during or after development, not as an initial design principle.
  • B. Security by obscurity relies on hiding vulnerabilities rather than fixing them, which is a poor security practice.
  • D. Penetration testing is a method of evaluating security by simulating an attack, typically performed after development.

Security by Design

An approach to software and system development that integrates security considerations and practices into every stage of the development lifecycle, from concept to deployment.

  • Proactive rather than reactive security.
  • Aims to prevent vulnerabilities from being introduced.
  • Often more cost-effective than fixing issues later.

Memory trick: Build security in from the start, don't just patch holes later.

More Basics of IT and Governance questions