On the other hand, approve, implement, and deny choices do not require additional testing and analysis because management is already satisfied with the testing and analysis.
21. During the initiation phase of a system development life cycle (SDLC) process, which of the following tasks is not typically performed?
a.
Preliminary risk assessmentb.
Preliminary system security plansc.
High-level security test plansd.
High-level security system architecture22. Security controls are designed and implemented in which of the following system development life cycle (SDLC) phases?
a.
Initiationb.
Development/acquisitionc.
Implementationd.
Disposal23. Product acquisition and integration costs are determined in which of the following system development life cycle (SDLC) phases?
a.
Initiationb.
Development/acquisitionc.
Implementationd.
Disposal24. A formal authorization to operate an information system is obtained in which of the following system development life cycle (SDLC) phases?
a.
Initiationb.
Development/acquisitionc.
Implementationd.
Disposal25. Which of the following gives assurance as part of system’s security and functional requirements defined for an information system?
a.
Access controlsb.
Background checks for system developersc.
Awarenessd.
Training26. System users must perform which of the following when new security controls are added to an existing application system?
a.
Unit testingb.
Subsystem testingc.
Full system testingd.
Acceptance testing27. Periodic reaccreditation of a system is done in which of the following system development life cycle (SDLC) phases?
a.
Initiationb.
Development/acquisitionc.
Implementationd.
Operation/maintenance28. Which of the following tests is driven by system requirements?
a.
Black-box testingb.
White-box testingc.
Gray-box testingd.
Integration testingWhite-box testing, also known as structural testing, examines the logic of the units and may be used to support software requirements for test coverage, i.e., how much of the program has been executed.