Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 92
In software acceptance testing, what is the purpose of compliance acceptance testing?
- A To ensure the software perform as expected in our live environment vs. our development environment.
- B To ensure the backups are in place, we have a DR plan, how patching is handled and that the software is tested for vulnerabilities.
- C To ensure the software is as secure or more secure than the rules, laws and regulations of our industry.
- D To ensure the software is functional for and tested by the end user and the application manager.
Reveal correct answer
Correct answer: C
Explanation
The correct answer: Compliance acceptance testing is a type of software acceptance testing that is focused on ensuring that the software meets the rules, laws, and regulations of the industry in which it will be used. This includes things like data privacy laws, security regulations, and other industry-specific requirements. By performing compliance acceptance testing, organizations can ensure that their software is as secure or more secure than the requirements of their industry, which helps to protect against legal and regulatory issues. The incorrect answers: Ensuring that backups are in place, that a disaster recovery plan is in place, and that patching and vulnerability testing are being properly handled describes several essential aspects of IT operations and security, including backups, disaster recovery (DR), patch management, and vulnerability testing. While these are all important aspects of maintaining a secure and resilient system, they are not the primary focus of compliance acceptance testing, which is more about ensuring legal and regulatory compliance. Ensuring that the software performs as expected in the live environment compared to the development environment describes a form of acceptance testing known as operational acceptance testing, or production acceptance testing. This form of testing aims to validate whether a system meets the requirements for operation and deployment, which is different from compliance acceptance testing. Ensuring that the software is functional for and tested by the end user and the application manager is a general aspect of software acceptance testing, but it is not specifically related to compliance acceptance testing.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
