Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsMedium

A project manager is overseeing the development of a new software application. To minimize security vulnerabilities from the outset, the team is adopting practices such as performing threat modeling early in the design phase, conducting regular code reviews, and integrating security testing into every stage of the software development lifecycle. Which cybersecurity concept is this organization primarily embracing?

  1. ASecurity by Design
  2. BRisk Acceptance
  3. CDefense in Depth
  4. DPrinciple of Least Privilege
Show answer & explanation

Correct answer: A. Security by Design

Integrating security practices like threat modeling, code reviews, and security testing throughout the software development lifecycle from the beginning is the core tenet of 'Security by Design', aiming to build security in, rather than bolt it on.

Why the other options are wrong

  • B. Risk Acceptance is a risk management strategy, not a development methodology.
  • C. Defense in Depth involves multiple layers of security controls, not specifically software development practices.
  • D. Principle of Least Privilege grants minimum necessary access, a specific access control concept.

Security by Design

The practice of building security into software, systems, and processes from the initial design phase, rather than adding it as an afterthought.

  • Integrates security throughout the SDLC.
  • Proactive approach to security.
  • Reduces vulnerabilities and costs in the long run.
  • Includes threat modeling, secure coding, security testing.

Memory trick: Design security in, don't just add it later.

More Cybersecurity Fundamentals questions