Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 4Objective 3

Apply the Secure Software Development Life Cycle (SDLC) CCSP Practice Questions (Page 2)

Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
16%of the exam

Questions 6–10

  1. 6application · medium

    A developer is writing a function that queries a cloud database. The function constructs a query by concatenating user input directly into the SQL string. Which secure coding practice should the developer apply to prevent SQL injection?

    Select an answer first
  2. 7application · medium

    A developer is implementing a file upload feature for a cloud application. The application will accept PDF files from users. Which secure coding practice is most important to prevent a malicious PDF from exploiting a vulnerability in the PDF parser?

    Select an answer first
  3. 8expert · hard

    A company is adopting a DevOps model and moving to a cloud environment. The security team is concerned about the lack of visibility and control over the development pipeline. They want to implement a control that provides the most comprehensive visibility into code changes and deployments while maintaining the agility of the DevOps process. Which control best balances these needs?

    Select an answer first
  4. 9application · medium

    A development team is writing a new REST API for a cloud application. The security lead instructs the team to follow OWASP ASVS to ensure the API is secure. Which ASVS requirement is most directly relevant to preventing injection attacks?

    Select an answer first
  5. 10application · medium

    A development team is using a version control system to manage code for a cloud application. They want to ensure that the code that is deployed to production is exactly the code that was reviewed and approved. Which configuration management practice should they implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.