On the other hand, approve, implement, and deny choices do not require additional testing and analysis because management is already satisfied with the testing and analysis.
21. During the initiation phase of a system development life cycle (SDLC) process, which of the following tasks is not typically performed?
a. Preliminary risk assessment
b. Preliminary system security plans
c. High-level security test plans
d. High-level security system architecture
22. Security controls are designed and implemented in which of the following system development life cycle (SDLC) phases?
a. Initiation
b. Development/acquisition
c. Implementation
d. Disposal
23. Product acquisition and integration costs are determined in which of the following system development life cycle (SDLC) phases?
a. Initiation
b. Development/acquisition
c. Implementation
d. Disposal
24. A formal authorization to operate an information system is obtained in which of the following system development life cycle (SDLC) phases?
a. Initiation
b. Development/acquisition
c. Implementation
d. Disposal
25. Which of the following gives assurance as part of system’s security and functional requirements defined for an information system?
a. Access controls
b. Background checks for system developers
c. Awareness
d. Training
26. System users must perform which of the following when new security controls are added to an existing application system?
a. Unit testing
b. Subsystem testing
c. Full system testing
d. Acceptance testing
27. Periodic reaccreditation of a system is done in which of the following system development life cycle (SDLC) phases?
a. Initiation
b. Development/acquisition
c. Implementation
d. Operation/maintenance
28. Which of the following tests is driven by system requirements?
a. Black-box testing
b. White-box testing
c. Gray-box testing
d. Integration testing
White-box testing, also known as structural testing, examines the logic of the units and may be used to support software requirements for test coverage, i.e., how much of the program has been executed.