Which Testing Team Blends Offensive and Defensive Work With Developers?

Explain types and purposes of audits and assessments. Explain various activities associated with vulnerability management.
Answer Correct answer: B — The yellow team applies both offensive and defensive testing methods alongside developers to securely build key applications and software.

Which of the following testing techniques uses both defensive and offensive testing methodologies with developers to securely build key applications and software?

  1. Blue
  2. Yellow Correct Answer
  3. Red
  4. Green

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This item tests whether you can separate the colored security teams by mission, and the trap is defaulting to red (offense) or blue (defense) when the phrase 'with developers' is the discriminator that only fits the yellow team.

SY0-701 team-color questions require matching each colored team to its function: the yellow team combines offensive and defensive perspectives while working directly with developers to build security into key applications. The answer is B (Yellow), because blue is purely defensive, red is purely offensive, and green pursues automated security improvement.

Picking C (Red) because red teams perform offensive testing, while ignoring that the question demands both offensive and defensive work performed alongside developers building applications — which is the yellow team's role.

Community Discussion (4 comments)

Anyio 👍 2 Selected: B
B. Yellow Explanation: The Yellow Team is a relatively newer concept in cybersecurity testing that combines both defensive (Blue Team) and offensive (Red Team) methodologies. This team works with developers to securely build key applications and software by integrating security practices throughout the development lifecycle, also known as Secure Development Lifecycle (SDLC). Their focus is on proactively addressing vulnerabilities while also testing the application for security flaws from an attacker's perspective. Why not the other options? C. Red Team: The Red Team conducts offensive testing by simulating real-world attacks to identify vulnerabilities and weaknesses. They don't directly engage with developers to build secure applications; they focus on penetration testing and exploitation.
Fhaddad81 👍 1 Selected: B
Yellow Team Objective: Ensure secure software and application development
bobacus2 👍 3 Selected: B
The yellow team is the group that, during application building, makes sure everything is secure. it is not A) Blue team - this team is purely defensive C) Red team - this team is purely offensive D) Green team - this team attempts to improve security by automating it
9149f41 👍 1 Selected: C
The correct answer is C. Red. Red team testing involves both defensive and offensive methodologies to identify and address security vulnerabilities in applications and software

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario asks for the testing team that pairs offensive and defensive methodologies and collaborates with developers to build key applications and software securely, which is the defining mission of the yellow team. Yellow team work is embedded in the build: it reviews code, threat-models new features and validates that security requirements survive the development lifecycle rather than testing only after release. Blue team work is defensive monitoring and hardening, red team work is adversarial offense, and green team work is automating and improving security controls, so none of those carry the 'with developers' element. Community consensus is strong here: bobacus2 writes that the yellow team is "the group that, during application building, makes sure everything is secure", and Anyio explains it is a newer concept that "combines both defensive (Blue Team) and offensive (Red Team) methodologies". That blend plus developer collaboration matches the question's wording exactly.

Why the Other Options Are Wrong

A (Blue) describes the purely defensive side of security operations — monitoring, alerting, log review and hardening — with no offensive testing role. C (Red) is the opposing pure-offense team that emulates adversaries through penetration testing and does not own secure build collaboration with developers. D (Green) is the automation-oriented team that improves security by scripting, orchestrating and automating controls and remediation, not by blending offense and defense during application development. The lone dissenting vote from 9149f41 for red reflects a common but incorrect assumption that red teams perform both offense and defense; in exam doctrine red is offense and the offensive-plus-defensive mix belongs to purple, while the developer-facing build role is yellow.

Community Comment Notes

Learners overwhelmingly converged on B, and the reasoning in the comments tracks the option set rather than just the vote count. bobacus2 draws the clean contrast that blue is purely defensive, red purely offensive and green is about automating security, which is precisely the elimination logic the exam expects. Anyio adds the useful framing that the yellow team is a newer, SDLC-focused concept that fuses blue and red perspectives while working with programmers. Fhaddad81 goes straight to the objective, stating the yellow team's goal is to "ensure secure software and application development", which mirrors the question's phrasing about securely building key applications and software. The only counterpoint, from 9149f41 choosing C, is worth noting because it shows the exact red-versus-yellow confusion this item is designed to catch.

Exam Strategy

Memorize the team-color table as role definitions, not colors: blue defends, red attacks, purple integrates both, white referees and sets rules of engagement, green automates improvements and yellow builds securely with developers. When a question adds a qualifier such as 'with developers' or 'during application building', treat it as the deciding keyword before you lock in an answer.

Frequently Asked Questions

Why is red team (C) wrong if red teams do offensive testing?

Red team doctrine in SY0-701 is purely offensive adversary emulation. The question requires defensive work performed with developers during application building, which describes the yellow team instead.

How is the yellow team different from the green team?

Green team focuses on improving security through automation, scripting and orchestration. Yellow team instead works hands-on with developers to embed security into the build of key applications and software.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide