Courseiva
Risk ManagementhardMultiple ChoiceObjective-mapped

ISC Risk Management Practice Question

When integrating risk management with the SDLC, which activity represents the most effective 'Shift-Left' approach to mitigate design-level risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Threat Modeling

Threat modeling during the design phase identifies architectural risks before code is written.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Static Application Security Testing (SAST)

    Why it's wrong here

    Occurs after code is written.

  • Threat Modeling

    Why this is correct

    Threat modeling is the gold standard for identifying design risks early.

  • Dynamic Application Security Testing (DAST)

    Why it's wrong here

    DAST occurs late in the SDLC.

  • Penetration Testing

    Why it's wrong here

    Occurs post-deployment.

About these practice questions

One of 219 original ISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official (ISC)² exam blueprint

This ISC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ISC exam.