Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 4Objective 3

Apply the Secure Software Development Life Cycle (SDLC) CCSP Practice Questions (Page 4)

Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
16%of the exam

Questions 16–20

  1. 16expert · hard

    A company is developing a cloud application that will be deployed in multiple regions. The legal team requires that the application's code and data be subject to the laws of the country where the data is processed. The development team is concerned about the CSP's ability to access the code and data. Which approach best addresses the legal/jurisdiction issue while maintaining the ability to develop and deploy the application?

    Select an answer first
  2. 17application · medium

    A development team is building a serverless application that processes user-uploaded images. The images are stored in cloud object storage and processed by a function. The security review identifies that the function's input validation is insufficient. Which secure coding practice directly addresses the risk of malicious file uploads leading to code execution?

    Select an answer first
  3. 18foundation · easy

    Which threat modeling methodology categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege?

    Select an answer first
  4. 19application · medium

    A development team is using OWASP ASVS to guide the security testing of a web application. They want to verify that the application does not expose sensitive data in URLs. Which ASVS requirement should they test?

    Select an answer first
  5. 20foundation · easy

    Which threat modeling methodology uses the acronym DREAD to rate and prioritize threats?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.