Which of the following practices would be best to prevent an insider from introducing malicious code into a company's development process?
Choose an answer
Tap an option to check your answer.
Correct answer: Peer review and approval.
Why this is the answer
Peer review and approval is the most effective practice because it involves multiple individuals examining code changes before they are integrated. This collaborative approach increases the likelihood of detecting malicious code, backdoors, or logic bombs that an insider might attempt to introduce. It also establishes accountability and acts as a deterrent. While code scanning for vulnerabilities is crucial, it primarily focuses on known vulnerabilities and may not detect intentionally malicious, novel code introduced by an insider. Open-source component usage, while beneficial for development speed, doesn't inherently prevent an insider from adding malicious code to the company's proprietary development. Quality assurance testing focuses on functionality and performance, and while it might uncover issues caused by malicious code, it's not designed to specifically detect malicious intent or hidden backdoors.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed