Which Topics Are Typically Included in an Organization's SDLC?

Which of the following topics would most likely be included within an organization's SDLC?

  1. Service-level agreements
  2. Information security policy
  3. Penetration testing methodology
  4. Branch protection requirements Source Reference Answer

Community Votes

D
39%
C
36%
B
24%

39% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to distinguish between continuous SDLC workflow controls and one-time assessments or high-level governance documents.

This question evaluates knowledge of Secure SDLC integration, with strong community consensus identifying branch protection requirements as a core developmental control. It underscores the CompTIA focus on DevSecOps practices over traditional, siloed security testing.

Candidates frequently select penetration testing methodology, assuming the testing phase dominates SDLC discussions. However, CompTIA prioritizes embedded development safeguards like version control gates over discrete external testing methods.

Community Discussion (20 comments)

Cee007 👍 8 Selected: D
D. Branch protection requirements Branch protection requirements are related to the version control and development process within the SDLC, ensuring that code changes are reviewed, tested, and approved before being merged into main branches. This helps maintain code quality and security throughout the development process. Penetration testing is usually conducted as part of the testing phase or after deployment to identify vulnerabilities and security weaknesses. It is a separate process from the core stages of the SDLC but is an important aspect of ensuring the security and robustness of the application once development is completed.
Konversation 👍 1 Selected: D
The CompTIA Sec+ Student Guide defines SDLC as: "SDLC policies govern software development within an organization. These policies provide a structured plan detailing the stages of development from initial requirement analysis to maintenance after deployment. It ensures that all software produced meets the organization’s efficiency, reliability, and security standards." Based on this definition, the answer "D" fits best. A: the SLA is related to a third party B: the InfoSec Policy is a high-level policy. It can contain SDLC requirements, but does not provide detailed standard requirements. C: Penetration testing method defined by CompTIA is more holistic view and not app-coding. Especially, there are some questions, where it is about how to secure own code and the answer is "peer reviews" and not pen-testing. D: I know SDLC as part of policies/guidelines for End-User-Computing (EUC) or individual data processing (IDP) and they contain protection requirements and standards derived from a BIA or a PNA. Best of luck with your exam.
Dayabaran 👍 1 Selected: B
ChatGPT & Copilot says
9149f41 👍 3 Selected: C
Branch protection is not directly part of SDLC. However, the penetration test is. 1. Planning 2. Analysis 3. Design; 4. Implementation 5. Testing ( various testing, e.g. Penetration testing) 6. Deployment 7. Maintenance.
Clau95 👍 1 Selected: B
The Software Development Life Cycle (SDLC) includes policies and procedures to ensure secure and efficient software development. An Information Security Policy is a crucial part of SDLC because it defines security requirements
Layrhian01 👍 2 Selected: C
Chat gpt says The topic that would most likely be included within an organization's Software Development Life Cycle (SDLC) is:
jbmac 👍 1 Selected: D
The correct answer is: D. Branch protection requirements Explanation: The Software Development Life Cycle (SDLC) refers to the structured process for planning, creating, testing, and deploying software applications. Among the provided options, branch protection requirements would most likely be included in the SDLC as part of the version control process to ensure that changes to the codebase are reviewed, tested, and securely merged. Branch protection ensures that only authorized and verified code can be merged into critical branches (like the main or master branch), which helps maintain the security, quality, and stability of the software. It often involves using code reviews, automated testing, and other safeguards to protect the integrity of the development process.
laternak26 👍 1 Selected: D
Branch protection requirements are typically part of the Software Development Life Cycle (SDLC), specifically in the phase where code is managed and controlled. These requirements ensure that the code in version control systems (like Git) is protected from unauthorized or accidental changes. For example, branch protection can enforce rules such as requiring code reviews, preventing direct pushes to the main branch, or ensuring all tests pass before code is merged. These practices help maintain the quality and security of the codebase throughout the development lifecycle.
e2ba0ff 👍 1 Selected: C
SDLC Includes secure coding practices, code reviews, and testing standards
Cocopqr 👍 1 Selected: D
Software Development Life Cycle (SDLC) is a framework that defines the stages involved in developing software. It focuses on the technical aspects of software development, including requirements gathering, design, development, testing, and deployment. Branch protection requirements are directly related to the development process and ensure code quality and security. They typically involve rules for merging code, such as requiring code reviews and preventing direct pushes to the main branch
fmeox567 👍 2 Selected: C
C. Penetration testing methodology Here's why: The SDLC is a framework that outlines the process for developing, deploying, and maintaining systems or applications. It typically includes phases such as planning, requirements gathering, design, development, testing, deployment, and maintenance. Penetration testing methodology is directly tied to the testing and security assurance phases of the SDLC. Organizations often incorporate security assessments, such as penetration testing, into the development process to identify and mitigate vulnerabilities before deployment. GPT
Murtuza 👍 1 Selected: C
option like penetration testing methodology would more closely align with SDLC than the overarching Information Security Policy
User92 👍 1 Selected: D
Branch protection requirements are directly related to the software development process, particularly in version control and code management. These requirements help ensure that only reviewed and approved code is merged into the main branch, maintaining the integrity and quality of the software throughout its development lifecycle. Why not B: Information security policy is a broader organizational policy that governs overall security practices. Why not C: Penetration testing methodology is part of security testing but not specifically tied to the SDLC phases.
khank14 👍 1
so many different answers
dhewa 👍 2 Selected: B
This is because an information security policy outlines the guidelines and practices for protecting sensitive data throughout the development process.
Lavette 👍 1
C. Penetration testing methodology is often part of the SDLC, especially in the testing phase, to identify vulnerabilities in the software before it goes live. While the other options are important in the broader organizational policies and security management, they are not typically a direct part of the SDLC process.
cri88 👍 4 Selected: B
B. Information security policy An Information security policy is often included within an organization's Software Development Life Cycle (SDLC) because security considerations are critical during the design, development, and deployment phases of software development. The SDLC aims to integrate security measures throughout the process to protect against vulnerabilities and ensure compliance with security standards. Service-level agreements (A) are more related to contracts and service performance rather than the SDLC. Penetration testing methodology (C) is typically used for post-development testing, not a core part of the SDLC. Branch protection requirements (D) relate to source code management and version control, but they are not commonly included as a core topic of the SDLC. Thus, Information security policy aligns most closely with the SDLC's focus on incorporating security best practices throughout the software development process.
17f9ef0 👍 2 Selected: C
Answer is C
a4e15bd 👍 1 Selected: C
The correct answer is C in this context. Pen Testing methodology could be part of the SDLC and directly relevant to the testing and security assurance phases of software development. D is incorrect because Branch Protection Requirements is more related to security measures around the physical or network infrastructure not software development.
Ayokunle01 👍 1
B. Information security policy An organization's Software Development Life Cycle (SDLC) typically includes information security policy to ensure that software development aligns with the organization's overall security posture. This policy outlines security requirements, standards, and guidelines for software development.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Secure SDLC and DevSecOps Integration

The Software Development Life Cycle (SDLC) provides a structured framework for building software, but modern security certifications like SY0-701 emphasize the Secure SDLC (often called DevSecOps). In this model, security controls are baked into every phase rather than applied only at deployment.

Why Branch Protection Requirements Are Correct

Branch protection requirements are natively embedded in the development and version control stages of the SDLC. They enforce mandatory code reviews, prevent direct pushes to main branches, and trigger automated security scans. These controls act as continuous quality and security gates, directly aligning with CompTIA's definition of SDLC policies that govern development workflows and ensure code integrity.

Why the Other Options Fall Short

  • Service-level agreements (SLAs) belong to IT service management and vendor contracting, not software engineering processes.
  • Information security policy is a broad governance document that sets organizational expectations. While it informs the SDLC, it is not a procedural step within the development cycle itself.
  • Penetration testing methodology relates to the validation phase, but it is typically a scheduled, external audit rather than a continuous SDLC control. Community votes often split here, but the exam distinguishes between ongoing development safeguards and periodic assessments.
Ultimately, SY0-701 expects you to recognize that modern SDLC success relies on automated, version-control-driven security practices.

Official Reference

  • CompTIA Security+ SY0-701 Official Learning Objectives (Domain 4.1: Application and Host Security)
  • NIST Special Publication 800-218: Secure Software Development Framework (SSDF)

Exam Strategy

When analyzing SDLC questions, prioritize answers that reflect continuous, automated security controls integrated into the development workflow (e.g., code scanning, version control gates, CI/CD pipelines). Avoid selecting high-level policies or one-time testing methods unless the question explicitly isolates a specific SDLC phase.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide