Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Scrum PSM-I Exam - Topic 5 Question 103 Discussion

What are two good ways for a Scrum Team to ensure security concerns are satisfied? (Choose two.)
B) Add security concerns to the definition of ''Done''. and E) Have the Scrum Team create Product Backlog items for each concern.
A) Postpone the work until a specialist can perform a security audit and create a list of security-related Product Backlog items.
C) Add a Sprint to specifically resolve all security concerns.
D) Delegate the work to the concerned department.

Scrum PSM-I Exam - Topic 5 Question 103 Discussion

Actual exam question for Scrum's PSM-I exam
Question #: 103
Topic #: 5
[All PSM-I Questions]

What are two good ways for a Scrum Team to ensure security concerns are satisfied? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, E

According to the Scrum Guide1, the definition of ''Done'' is a formal description of the state of the Increment when it meets the quality measures required for the product. The definition guides the Development Team in creating a ''Done'' Increment. The definition of ''Done'' is created by the development organization (or Development Team if none is available from the development organization). The definition of ''Done'' may vary significantly per Scrum Team, depending on the context. One aspect of Scrum Teams inspecting how they work toward their Product Goal is that they improve their definition of ''Done'' over time. Therefore, one good way for a Scrum Team to ensure security concerns are satisfied is to add security concerns to the definition of ''Done''. Another good way is to have the Scrum Team create Product Backlog items for each concern, as they are responsible for managing and refining the Product Backlog.


Contribute your Thoughts:

0/2000 characters
Lachelle
2 hours ago
I feel like delegating the work to another department might not be the best idea. The Scrum Team should really be involved in addressing security issues directly.
upvoted 0 times
...
Ronald
5 days ago
I'm a bit confused about whether postponing work for a security audit is practical. It seems like it could slow down the team too much.
upvoted 0 times
...
Buffy
10 days ago
I remember a practice question where we discussed the importance of integrating security into the development process, so maybe creating Product Backlog items for each concern could work too.
upvoted 0 times
...
Dyan
16 days ago
I think adding security concerns to the definition of "Done" is definitely a good approach, but I'm not sure about the other option.
upvoted 0 times
...

Save Cancel