ITPEC IP April 2023 Question 63

Source exam: ITPEC IP April 2023Topic: System Development Technology

ITPEC IP April 2023 — Question 63 of 100

Access management and segregation-of-duties requirements must be considered from requirements definition. At that stage, the organization identifies user roles, permitted operations, conflicting duties, approval paths, audit needs, and sensitive data. Designing these controls early ensures the architecture and later implementation can enforce them.

Answer (a)

Why not others:
- (b) waiting until programming risks discovering that the design cannot support the required authorization model

- (c) testing should verify previously defined controls, not first decide what controls are needed

- (d) adding access control only after operations start leaves the system exposed and makes correction costly

Key rule: Security and internal-control requirements are system requirements, so they must shape design before code and testing.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.