easyMultiple ChoiceObjective-mapped
CISSP Practice Question: Is migrating from a waterfall to an Agile…
An organization is migrating from a waterfall to an Agile development methodology. Which of the following is a key security advantage of Agile?
⚠ Common exam trap
The trap here is conflating 'Agile' with 'no documentation' or 'no upfront planning,' when in reality Agile requires disciplined, just-in-time security activities and maintains necessary documentation for compliance and risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security issues can be addressed incrementally throughout development
In Agile development, security testing and remediation are integrated into each iteration (sprint), allowing teams to identify and fix vulnerabilities incrementally rather than waiting until the end. This continuous feedback loop reduces the risk of late-stage security surprises and aligns with the principle of 'shifting left' on security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security testing is performed only at the end of the project
Why it's wrong here
Performing security testing only at the end of the project is a characteristic of traditional waterfall models, not agile. Agile methodologies advocate for 'shifting left,' integrating security activities, including automated and manual testing, into every sprint and continuous integration pipeline. This allows for early detection and remediation of vulnerabilities, significantly reducing the cost and effort of fixing issues later in the development lifecycle.
- ✓
Security issues can be addressed incrementally throughout development
Why this is correct
Agile's iterative nature, characterized by short development cycles or sprints, inherently allows for security issues to be addressed incrementally. As security findings emerge from continuous testing, threat modeling, or code reviews within a sprint, they can be prioritized and remediated promptly in subsequent iterations. This continuous feedback loop ensures that security debt is minimized and risks are mitigated proactively throughout the entire development process.
- ✗
Security requirements are finalized upfront
Why it's wrong here
Finalizing all security requirements upfront contradicts the core agile principle of embracing change and iterative refinement. In an agile environment, security requirements, often expressed as security stories or acceptance criteria, evolve alongside functional requirements as the product develops and threat landscapes change. This allows for adaptive security measures rather than rigid, potentially outdated, upfront specifications.
- ✗
Security documentation is minimized to reduce overhead
Why it's wrong here
While agile promotes 'just enough' documentation over comprehensive, rigid artifacts, minimizing security documentation solely to reduce overhead is not inherently a security advantage. Critical security documentation, such as threat models, architectural security decisions, and compliance evidence, remains essential for maintaining traceability, auditability, and understanding the security posture. The focus should be on valuable, actionable documentation that supports security objectives, not its mere reduction.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.