A risk-based threat modeling approach is the best recommendation to prevent the recurrence of major process issues during the development lifecycle. Threat modeling identifies potential security threats, vulnerabilities, and design flaws early in the development process by focusing on the specific risks posed to the system. By proactively identifying and addressing security concerns before they escalate, the development team can avoid the need for significant rewrites and ensure that security is embedded into the design of new projects. CASP+ emphasizes threat modeling as a critical activity to improve secure development practices. Reference: CASP+ CAS-004 Exam Objectives: Domain 2.0 - Enterprise Security Operations (Threat Modeling and Risk-Based Security Approaches) CompTIA CASP+ Study Guide: Threat Modeling and Secure Development Lifecycle