How to Prevent Insider Injection of Malicious Code?

Which of the following practices would be best to prevent an insider from introducing malicious code into a company's development process?

  1. Code scanning for vulnerabilities
  2. Open-source component usage
  3. Quality assurance testing
  4. Peer review and approval Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the critical distinction between preventive and detective controls, with the trap being the selection of automated tools that identify flaws only after code has already been written.

This question evaluates understanding of proactive security controls within the SDLC to mitigate insider threats. The community consistently identifies peer review as the superior preventive measure over detection-focused alternatives.

Candidates frequently select A (Code scanning) due to its popularity in DevSecOps pipelines, but automated scanners only detect vulnerabilities post-introduction, failing to satisfy the 'prevent' requirement.

Community Discussion (4 comments)

geocis 👍 16
Correct Answer: D Peer review and approval is a practice that involves having other developers or experts review the code before it is deployed or released. Peer review and approval can help detect and prevent malicious code, errors, bugs, vulnerabilities, and poor quality in the development process. Peer review and approval can also enforce coding standards, best practices, and compliance requirements. Peer review and approval can be done manually or with the help of tools, such as code analysis, code review, and code signing. References: CompTIA Security+ Study Guide: Exam SY0-701, 9th Edition, Chapter 11: Secure Application Development, page 543 2
MarysSon 👍 1 Selected: D
The key word here is prevent. Code scanning reveals vulnerabilities that are already introduced to a system. Peer reviews are intended to check code prior to intruduction in a production system.
dbrowndiver 👍 2 Selected: D
Peer reviews help catch malicious code before it is integrated into the production environment by having multiple sets of eyes on the changes, reducing the chance of any one developer slipping harmful code through the process.
Shaman73 👍 1
D. Peer review and approval

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Preventive vs. Detective Controls

The question hinges on the keyword prevent. In security architecture, controls are categorized by their timing and function. Preventive controls stop incidents before they occur, while detective controls identify them after they have happened.

Why Peer Review and Approval is Correct

Peer review and approval directly addresses the prevention requirement by mandating that multiple developers or security experts examine code changes before they are merged into the main branch or deployed. As highlighted by community members, having multiple sets of eyes makes it significantly harder for a malicious insider to slip harmful code past unnoticed checks. It also enforces coding standards and compliance requirements, creating a collaborative environment where anomalies stand out immediately.

Why Other Options Are Incorrect

  • Code scanning for vulnerabilities (A) is a powerful detective control. While it can flag known vulnerability patterns, it operates on code that has already been written and committed. It cannot reliably distinguish between accidental bugs and intentional malicious payloads without prior context.
  • Open-source component usage (B) actually increases supply chain risk and has no bearing on stopping an internal developer from injecting malware.
  • Quality assurance testing (C) primarily validates functional requirements, performance, and user experience. QA teams typically test against expected behavior rather than security integrity or malicious intent.

Exam Takeaway

When a SY0-701 question asks how to prevent an insider threat or unauthorized change, prioritize human oversight mechanisms like peer reviews, mandatory approvals, separation of duties, or least privilege access over automated scanning or testing tools.

Official Reference

  • CompTIA Security+ SY0-701 Official Study Guide: Secure Software Development Lifecycle (SSDLC)
  • NIST SP 800-218: Secure Software Development Framework (SSDF)
  • OWASP SAMM (Software Assurance Maturity Model): Verification Practices

Exam Strategy

Always align your answer choice with the specific action verb in the question stem. Use 'prevent' to guide you toward proactive measures like peer reviews, access controls, or policy enforcement, and reserve 'detect' or 'identify' for monitoring, scanning, and auditing tools. If two answers seem plausible, choose the one that intervenes earliest in the development pipeline.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide