
Certified Cloud Security Professional
Domain 4Objective 3
Apply the Secure Software Development Life Cycle (SDLC) CCSP Practice Questions (Page 1)
Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
16%of the exam
Questions 1–5
- 1
A company is developing a cloud application that will be deployed in a region where the CSP is subject to government surveillance laws. The security team is concerned about the legal/jurisdiction risk. They want to implement a control that provides the strongest protection against unauthorized access by the CSP or government entities. Which control is most effective?
Select an answer first - 2
Which of the following is a cloud-specific risk that should be considered during the secure SDLC?
Select an answer first - 3
Which of the following is a common tool used for version control in software configuration management?
Select an answer first - 4
Which of the following is a common software vulnerability that can be mitigated by implementing output encoding?
Select an answer first - 5
A security team is using STRIDE to threat model a cloud application. They identify a threat where an attacker could modify data in transit between the application and the database. Which STRIDE category does this threat fall under?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.