Cisco CCNP Security Core (SCOR) 350-701Security ConceptsMedium

A company is developing a new mobile application that will handle sensitive customer data. Before deployment, they engage a third-party firm to conduct a comprehensive review of the application's source code, architecture, and deployment environment to identify design flaws and potential vulnerabilities. This activity is a form of:

  1. ASecurity Assessment
  2. BSecurity Metrics
  3. CSecurity Policy Enforcement
  4. DSecurity Reporting
Show answer & explanation

Correct answer: A. Security Assessment

A comprehensive review of source code, architecture, and environment to identify flaws and vulnerabilities is a form of security assessment. This umbrella term covers various evaluation activities like code reviews, penetration tests, and vulnerability assessments, all aimed at understanding security posture.

Why the other options are wrong

  • B. Security metrics are quantitative measures of security performance, not the assessment activity itself.
  • C. Security policy enforcement is ensuring adherence to rules, not the process of finding vulnerabilities.
  • D. Security reporting is the communication of assessment findings, not the assessment process.

Security Assessment

The process of evaluating the security posture of an information system, application, or network to identify vulnerabilities, risks, and control deficiencies.

  • Can include vulnerability scans, penetration tests, code reviews, and architecture reviews.
  • Aims to provide a comprehensive understanding of security weaknesses.
  • Often conducted by independent third parties.

Memory trick: Assessments 'ASSESS' what's 'SECURE' or 'NOT' in the 'SYSTEM'.

More Security Concepts questions