Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: Is migrating from a waterfall to an Agile…

An organization is migrating from a waterfall to an Agile development methodology. Which of the following is a key security advantage of Agile?

⚠ Common exam trap

The trap here is conflating 'Agile' with 'no documentation' or 'no upfront planning,' when in reality Agile requires disciplined, just-in-time security activities and maintains necessary documentation for compliance and risk management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Security issues can be addressed incrementally throughout development

In Agile development, security testing and remediation are integrated into each iteration (sprint), allowing teams to identify and fix vulnerabilities incrementally rather than waiting until the end. This continuous feedback loop reduces the risk of late-stage security surprises and aligns with the principle of 'shifting left' on security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security testing is performed only at the end of the project

    Why it's wrong here

    Performing security testing only at the end of the project is a characteristic of traditional waterfall models, not agile. Agile methodologies advocate for 'shifting left,' integrating security activities, including automated and manual testing, into every sprint and continuous integration pipeline. This allows for early detection and remediation of vulnerabilities, significantly reducing the cost and effort of fixing issues later in the development lifecycle.

  • Security issues can be addressed incrementally throughout development

    Why this is correct

    Agile's iterative nature, characterized by short development cycles or sprints, inherently allows for security issues to be addressed incrementally. As security findings emerge from continuous testing, threat modeling, or code reviews within a sprint, they can be prioritized and remediated promptly in subsequent iterations. This continuous feedback loop ensures that security debt is minimized and risks are mitigated proactively throughout the entire development process.

  • Security requirements are finalized upfront

    Why it's wrong here

    Finalizing all security requirements upfront contradicts the core agile principle of embracing change and iterative refinement. In an agile environment, security requirements, often expressed as security stories or acceptance criteria, evolve alongside functional requirements as the product develops and threat landscapes change. This allows for adaptive security measures rather than rigid, potentially outdated, upfront specifications.

  • Security documentation is minimized to reduce overhead

    Why it's wrong here

    While agile promotes 'just enough' documentation over comprehensive, rigid artifacts, minimizing security documentation solely to reduce overhead is not inherently a security advantage. Critical security documentation, such as threat models, architectural security decisions, and compliance evidence, remains essential for maintaining traceability, auditability, and understanding the security posture. The focus should be on valuable, actionable documentation that supports security objectives, not its mere reduction.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.