
Certified Cloud Security Professional
Domain 4Objective 3
Apply the Secure Software Development Life Cycle (SDLC) CCSP Practice Questions (Page 3)
Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
16%of the exam
Questions 11–15
- 11
A security team is conducting threat modeling for a cloud application that uses a serverless architecture. They want to identify threats that are specific to serverless, such as event injection and insecure deployment configurations. Which threat modeling methodology is best suited to address these cloud-specific threats?
Select an answer first - 12
Which of the following is a common software vulnerability that can be mitigated by using parameterized queries or prepared statements?
Select an answer first - 13
Which of the following is a secure coding standard/framework that provides a comprehensive set of security requirements for application development?
Select an answer first - 14
A development team uses a version control system (VCS) for their cloud application. They want to ensure that the codebase is protected from unauthorized changes and that any changes can be traced to a specific developer. Which configuration management practice should they implement?
Select an answer first - 15
A developer is implementing authentication for a cloud application. They want to prevent brute-force attacks on user accounts. Which secure coding practice is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.