How do you prove developers are trained on secure coding?

Which of the following is the act of proving to a customer that software developers are trained on secure coding?

  1. Assurance
  2. Contract
  3. Due diligence
  4. Attestation Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to distinguish attestation (formal proof/certification of a claim) from assurance (confidence in a system) and due diligence (pre-agreement risk evaluation).

Attestation is the formal act of providing evidence or certification that a specific requirement, such as secure coding training, has been met. Community consensus strongly confirms D as the correct answer for SY0-701.

Candidates often choose 'Assurance' because it implies confidence, but assurance is an ongoing state of confidence rather than the formal act of proving a specific condition to a third party.

Community Discussion (6 comments)

9149f41 👍 1 Selected: D
Due diligence refers to the comprehensive process of evaluating and mitigating risks before making a decision or entering into an agreement. So only attestation is the only reasonable answer.
1eccfc0 👍 2 Selected: D
Attestation is the act of formally proving or certifying that a specific requirement or standard has been met. In this case, it would involve providing evidence or documentation to a customer that software developers have been trained in secure coding practices
Cykhar 👍 1 Selected: D
Attestation.
1eccfc0 👍 1 Selected: D
The correct answer is D. Attestation. Attestation is the act of proving or certifying that a certain condition has been met, in this case, that software developers are trained on secure coding practices. It typically involves a formal declaration or verification by the organization. Assurance: Refers to confidence that a system or process meets certain requirements, but does not specifically involve proving training. Contract: A legal agreement between parties, not directly related to proving secure coding training. Due diligence: The process of investigating or verifying something thoroughly, but not specifically tied to proving training.
jsap 👍 1 Selected: D
Attestation is the act of formally proving or certifying something to be true. In this case, it refers to providing proof that software developers have been trained on secure coding practices. Attestation often involves documentation or certification that demonstrates compliance with specific standards or requirements.
ramzie 👍 1 Selected: D
The correct answer is D. Attestation Attestation which refers to a formal statement or record that confirms the truth or accuracy of certain claims. In this context, it can be used to demonstrate to customers that software developers have completed security training and are knowledgeable about secure coding practices. This includes providing evidence of training completion through certificates, documentation, or proof of participation in workshops. why not B, Contract. A contract defines responsibilities for both parties involved in a transaction or agreement but isn't directly about proving specific skills.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Attestation is defined as the formal act of providing evidence, certification, or a third-party declaration that a specific condition or standard has been satisfied. In this scenario, the organization must prove to a customer that developers completed secure coding training, which is precisely what attestation provides. Community members correctly note that attestation involves documentation, certificates, or formal verification to demonstrate compliance. This aligns perfectly with third-party risk management and supply chain security requirements in SY0-701.

Why the Other Options Are Wrong

Assurance (A) refers to the ongoing confidence that a system or process meets security requirements, but it does not constitute the formal act of proving a specific claim to a customer. Contract (B) is a legally binding agreement between parties and does not inherently serve as proof of training completion. Due diligence (C) is the investigative process performed before entering an agreement to evaluate risks, not the act of certifying that a requirement has already been met. Comments consistently reinforce that only attestation fits the definition of formally proving a condition.

Community Comment Notes

All six community comments unanimously support answer D, with multiple users emphasizing that attestation involves formal certification or documentation. Comment [3] provides a particularly clear distinction between attestation and assurance, noting that assurance does not specifically involve formal proof. Comment [2] correctly eliminates due diligence by defining it as a pre-decision evaluation process. The strong consensus (100% votes for D) indicates this is a straightforward definition-based question with little ambiguity.

Official Reference

Exam Strategy

When you see 'proving to a customer' or 'formal declaration,' immediately think of attestation. Memorize the triad: attestation = formal proof, assurance = confidence level, due diligence = pre-agreement investigation.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide