SY0-701 exam dumps

SY0-701 practice question 487 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 487

Single answerDevelopment

A software development team is preparing to release a new customer-facing web application. During a pre-release review, the security analyst finds that developers have been testing code directly in production-like systems using shared administrator accounts, and security defects are often discovered late in the project after major features are already complete. Management wants to reduce security risk without significantly slowing development. Which of the following is the BEST approach to address these issues?

  1. A

    Implement a secure SDLC with separate development, testing, and production environments, enforce individual accounts with least privilege, and add security testing earlier in the pipeline

  2. B

    Require developers to use the shared administrator account only during scheduled maintenance windows so activity is easier to monitor

  3. C

    Move all security testing to the final acceptance phase so the development team can focus on feature delivery first

  4. D

    Allow developers to continue testing in production-like systems, but require them to change the shared administrator password after each release

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement a secure SDLC with proper environment separation, identity-based accountability, and earlier security validation. In Security+ terms, this aligns with secure development practices such as development/testing/staging/production separation, least privilege, and integrating security into the software lifecycle rather than treating it as an afterthought. Industry best practices from NIST's Secure Software Development Framework (SSDF), OWASP guidance, and common DevSecOps models emphasize shifting security left, maintaining separate environments, and avoiding shared accounts for administrative activities. These controls reduce operational risk, improve traceability, and help organizations find and fix vulnerabilities earlier when remediation is less costly.

  • A. Correct.

    Correct. This directly addresses the core development security problems in the scenario: lack of environment separation, use of shared privileged accounts, and late discovery of vulnerabilities. A secure software development life cycle (SDLC), often aligned with DevSecOps practices, incorporates security requirements and testing early and throughout development. Separate environments reduce the risk of accidental impact to production data and systems. Individual accounts support accountability and auditing, while least privilege limits the damage from mistakes or compromise.

  • B. Incorrect.

    Incorrect. Restricting use of a shared administrator account to maintenance windows does not solve the accountability problem. Shared accounts make it difficult to attribute actions to a specific user, weakening audit trails and non-repudiation. It also preserves excessive privilege rather than reducing it. Someone might choose this option because monitoring sounds helpful, but the underlying control weakness remains.

  • C. Incorrect.

    Incorrect. Delaying security testing until final acceptance is contrary to secure development best practices. Finding defects late typically increases remediation cost and project disruption. This option reflects a common misconception that security is a final checkpoint instead of an activity integrated throughout development. Early testing such as code review, static analysis, dependency checking, and pre-release validation is more effective.

  • D. Incorrect.

    Incorrect. Changing the password after each release is better than never rotating it, but it does not address the main issue: shared privileged credentials and unsafe testing practices. Developers would still be using a common high-privilege account, preventing strong accountability and violating least-privilege principles. It also does not improve when security issues are found in the development process.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam