Which Topics Are Typically Included in an Organization's SDLC?
Which of the following topics would most likely be included within an organization's SDLC?
Community Votes
39% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your ability to distinguish between continuous SDLC workflow controls and one-time assessments or high-level governance documents.
This question evaluates knowledge of Secure SDLC integration, with strong community consensus identifying branch protection requirements as a core developmental control. It underscores the CompTIA focus on DevSecOps practices over traditional, siloed security testing.
Candidates frequently select penetration testing methodology, assuming the testing phase dominates SDLC discussions. However, CompTIA prioritizes embedded development safeguards like version control gates over discrete external testing methods.
Community Discussion (20 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Secure SDLC and DevSecOps Integration
The Software Development Life Cycle (SDLC) provides a structured framework for building software, but modern security certifications like SY0-701 emphasize the Secure SDLC (often called DevSecOps). In this model, security controls are baked into every phase rather than applied only at deployment.Why Branch Protection Requirements Are Correct
Branch protection requirements are natively embedded in the development and version control stages of the SDLC. They enforce mandatory code reviews, prevent direct pushes to main branches, and trigger automated security scans. These controls act as continuous quality and security gates, directly aligning with CompTIA's definition of SDLC policies that govern development workflows and ensure code integrity.Why the Other Options Fall Short
- Service-level agreements (SLAs) belong to IT service management and vendor contracting, not software engineering processes.
- Information security policy is a broad governance document that sets organizational expectations. While it informs the SDLC, it is not a procedural step within the development cycle itself.
- Penetration testing methodology relates to the validation phase, but it is typically a scheduled, external audit rather than a continuous SDLC control. Community votes often split here, but the exam distinguishes between ongoing development safeguards and periodic assessments.
Official Reference
- CompTIA Security+ SY0-701 Official Learning Objectives (Domain 4.1: Application and Host Security)
- NIST Special Publication 800-218: Secure Software Development Framework (SSDF)
Exam Strategy
When analyzing SDLC questions, prioritize answers that reflect continuous, automated security controls integrated into the development workflow (e.g., code scanning, version control gates, CI/CD pipelines). Avoid selecting high-level policies or one-time testing methods unless the question explicitly isolates a specific SDLC phase.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →