New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CSSLP Exam - Topic 2 Question 71 Discussion

Actual exam question for ISC2's CSSLP exam
Question #: 71
Topic #: 2
[All CSSLP Questions]

What are the various activities performed in the planning phase of the Software Assurance Acquisition process? Each correct answer represents a complete solution. Choose all that apply.

Show Suggested Answer Hide Answer
Suggested Answer: D

Graybox testing is a combination of whitebox testing and blackbox testing. In graybox testing, the test engineer is equipped with the

knowledge of system and designs test cases or test data based on system knowledge. The security tester typically performs graybox testing

to find vulnerabilities in software and network system.

Answer C is incorrect. Whitebox testing is a testing technique in which an organization provides full knowledge about the infrastructure

to the testing team. The information, provided by the organization, often includes network diagrams, source codes, and IP addressing

information of the infrastructure to be tested.

Answer A is incorrect. Integration testing is a logical extension of unit testing. It is performed to identify the problems that occur when

two or more units are combined into a component. During integration testing, a developer combines two units that have already been tested

into a component, and tests the interface between the two units. Although integration testing can be performed in various ways, the

following three approaches are generally used:

The top-down approach

The bottom-up approach

The umbrella approach

Answer B is incorrect. Regression testing can be performed any time when a program needs to be modified either to add a feature or

to fix an error. It is a process of repeating Unit testing and Integration testing whenever existing tests need to be performed again along with

the new tests. Regression testing is performed to ensure that no existing errors reappear, and no new errors are introduced.


Contribute your Thoughts:

0/2000 characters
Kenia
3 months ago
Not sure if all these are necessary in the planning phase.
upvoted 0 times
...
Nu
3 months ago
Creating an acquisition strategy is a must!
upvoted 0 times
...
Keneth
4 months ago
Wait, are we sure about the evaluation criteria part?
upvoted 0 times
...
William
4 months ago
I think implementing change control is crucial too.
upvoted 0 times
...
Malcolm
4 months ago
Definitely need to develop software requirements!
upvoted 0 times
...
Luther
4 months ago
I'm a bit confused about change control procedures; I thought they were more relevant during the implementation phase rather than planning.
upvoted 0 times
...
Bambi
4 months ago
I practiced a similar question, and I believe developing evaluation criteria and an evaluation plan is also important in this phase.
upvoted 0 times
...
Tien
5 months ago
I think creating an acquisition strategy is crucial, but I can't recall if implementing change control procedures fits in the planning phase.
upvoted 0 times
...
Reita
5 months ago
I remember that developing software requirements is definitely part of the planning phase, but I'm not sure about the others.
upvoted 0 times
...
Penney
5 months ago
I'm a little confused by the options here. Sdp-ping, Isp-ping, Svc-ping - they all sound similar. I'll have to review my notes on the 7750 SR OAM tools to make sure I understand the differences between them before answering this.
upvoted 0 times
...
Delpha
5 months ago
This looks like a question about data management and compliance. I'll need to think carefully about the different dimensions and which one focuses on industry regulations.
upvoted 0 times
...
Lore
5 months ago
I'm a little stuck on this question. I'll need to think through the best practices for closing a negotiation and how the procurement team should conduct themselves. I don't want to make any assumptions.
upvoted 0 times
...
Alison
9 months ago
Hmm, let's see. Software requirements, check. Change control, check. Evaluation criteria and plan, check. Acquisition strategy, check. Wait, where's the 'Bring Snacks and Hire a DJ' option? Gotta keep the planning phase fun, you know!
upvoted 0 times
Karan
8 months ago
D) Create acquisition strategy.
upvoted 0 times
...
Shala
8 months ago
C) Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
Sharan
8 months ago
B) Implement change control procedures.
upvoted 0 times
...
Julene
8 months ago
Good point, we can always add some fun elements later on!
upvoted 0 times
...
Jacquelyne
8 months ago
True, but I think we'll stick to the traditional activities for now.
upvoted 0 times
...
Laurel
8 months ago
Haha, 'Bring Snacks and Hire a DJ' would definitely make the planning phase more enjoyable!
upvoted 0 times
...
Micaela
8 months ago
D) Create acquisition strategy.
upvoted 0 times
...
Tamala
8 months ago
C) Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
Nguyet
8 months ago
B) Implement change control procedures.
upvoted 0 times
...
Floyd
9 months ago
A) Develop software requirements.
upvoted 0 times
...
Phillip
9 months ago
A) Develop software requirements.
upvoted 0 times
...
...
Meaghan
10 months ago
Alright, let's do this! Software requirements, check. Change control, check. Evaluation criteria and plan, check. Acquisition strategy, check. I feel like I just aced the 'How to Organize a Software Party' exam.
upvoted 0 times
Kris
9 months ago
Laurel: Create acquisition strategy.
upvoted 0 times
...
Barbra
9 months ago
User 3: Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
Laurel
9 months ago
User 2: Implement change control procedures.
upvoted 0 times
...
Tamar
9 months ago
User 1: Develop software requirements.
upvoted 0 times
...
...
Clemencia
10 months ago
Wait, wait, wait. Planning phase, you say? I thought this was the 'Wing It and Pray' phase. But hey, I guess I'll take the 'Develop evaluation criteria and evaluation plan' option. Sounds like a good way to keep the chaos at bay.
upvoted 0 times
Lavera
9 months ago
Implement change control procedures.
upvoted 0 times
...
Ben
9 months ago
Create acquisition strategy.
upvoted 0 times
...
Lashawn
9 months ago
Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
...
Nan
10 months ago
Okay, let's see here. Developing software requirements, check. Implementing change control, got it. Evaluation criteria and plan, absolutely. And don't forget the acquisition strategy. Nailed it!
upvoted 0 times
Barrett
8 months ago
Creating an acquisition strategy is key in the planning phase.
upvoted 0 times
...
Mariann
8 months ago
Developing evaluation criteria and evaluation plan is a must.
upvoted 0 times
...
Silvana
8 months ago
Implementing change control procedures is definitely important.
upvoted 0 times
...
Leota
8 months ago
I agree, developing software requirements is crucial.
upvoted 0 times
...
Rikki
8 months ago
And we must create an acquisition strategy as well.
upvoted 0 times
...
Emeline
8 months ago
Let's not forget about developing evaluation criteria and plan.
upvoted 0 times
...
Honey
8 months ago
Yes, and we also need to implement change control procedures.
upvoted 0 times
...
Ilda
10 months ago
I think we need to develop software requirements.
upvoted 0 times
...
...
Julene
10 months ago
I believe implementing change control procedures is also important in the planning phase to ensure smooth execution of the software acquisition process.
upvoted 0 times
...
Serita
10 months ago
I agree with Verda. Developing software requirements, evaluation criteria, and acquisition strategy are crucial in the planning phase.
upvoted 0 times
...
Erick
11 months ago
Ah, the planning phase! That's where the real magic happens. Let's see, we've got software requirements, change control, evaluation criteria, and acquisition strategy. Sounds like a party waiting to happen!
upvoted 0 times
Matilda
9 months ago
Create acquisition strategy.
upvoted 0 times
...
Lynda
9 months ago
Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
Jin
9 months ago
Implement change control procedures.
upvoted 0 times
...
Monte
9 months ago
D) Create acquisition strategy.
upvoted 0 times
...
Merlyn
9 months ago
Develop software requirements.
upvoted 0 times
...
Steffanie
9 months ago
C) Develop evaluation criteria and evaluation plan.
upvoted 0 times
...
Gilma
9 months ago
B) Implement change control procedures.
upvoted 0 times
...
Shalon
10 months ago
A) Develop software requirements.
upvoted 0 times
...
...
Verda
11 months ago
I think A, C, and D are performed in the planning phase.
upvoted 0 times
...

Save Cancel