Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

APICS CPIM-8.0 Exam - Topic 4 Question 25 Discussion

The development team wants new commercial software to integrate into the current system. What steps can the security office take to ensure the software has no vulnerabilities?
B) Request a copy of the most recent System and Organization Controls (SOC) report and/or most recent security audit reports and any vulnerability scans of the software code from the vendor.
A) Ask the development team to reevaluate the current program and have a toolset developed securely within the organization.
C) Purchase the software, deploy it in a test environment, and perform Dynamic Application Security Testing (DAST) on the software.
D) Request a software demo with permission to have a third-party penetration test completed on it.

APICS CPIM-8.0 Exam - Topic 4 Question 25 Discussion

Actual exam question for APICS's CPIM-8.0 exam
Question #: 25
Topic #: 4
[All CPIM-8.0 Questions]

The development team wants new commercial software to integrate into the current system. What steps can the security office take to ensure the software has no vulnerabilities?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
I vaguely recall something about secure development practices in our coursework. Option A might help, but I’m not confident it’s the most effective step compared to the others.
upvoted 0 times
...
Rochell
5 days ago
I feel like option D could be a good way to ensure security, but I wonder how often vendors agree to third-party tests. It seems like a lot of trust is involved.
upvoted 0 times
...
Kasandra
10 days ago
I think option C makes sense too, especially since we practiced DAST in our labs. But what if the test environment doesn't reflect the production environment accurately?
upvoted 0 times
...
Valene
15 days ago
I remember we discussed the importance of getting SOC reports from vendors, so option B seems like a solid choice. But I'm not entirely sure if that's enough on its own.
upvoted 0 times
...

Save Cancel