Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A software development team is adopting a 'shift-left' security approach, integrating security testing and code reviews earlier in the development lifecycle. This aims to identify and remediate vulnerabilities before they reach production. Which security concept does this strategy best exemplify?

  1. ASecurity best practices
  2. BSecurity operations
  3. CSecurity reporting
  4. DSecurity metrics
Show answer & explanation

Correct answer: A. Security best practices

Integrating security early in the development lifecycle is a widely recognized and recommended 'security best practice' for modern software development, often referred to as DevSecOps or 'shift-left'.

Why the other options are wrong

  • B. Security operations focuses on real-time monitoring and incident response, not development methodology.
  • C. Security reporting communicates status, not the underlying development approach.
  • D. Security metrics measure performance; this scenario describes an approach, not its measurement.

Security Best Practices

Recommended methods, procedures, or techniques that are generally accepted as the most effective ways to achieve a security objective, often based on industry standards or expert consensus.

  • Examples include 'least privilege', 'defense in depth', 'zero trust', 'shift-left'.
  • Help organizations build robust security programs and reduce risk.
  • Are continuously evolving with new threats and technologies.

Memory trick: Best practices make security better, stronger, faster.

More Security Concepts questions