
Certified Cloud Security Professional
Domain 4Objective 2
Describe the Secure Software Development Life Cycle (SDLC) Process CCSP Practice Questions (Page 3)
Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
4concepts
16%of the exam
Questions 11–15
- 11
A development team is using a CI/CD pipeline to build and deploy a microservices-based application. The security team wants to ensure that vulnerabilities are caught early and that security is not an afterthought. Which action is most effective?
Select an answer first - 12
A government agency is developing a system with strict regulatory requirements and a fixed, non-negotiable delivery date. The project manager wants to ensure that security is thoroughly documented and reviewed at each phase. Which SDLC methodology is most appropriate for this environment?
Select an answer first - 13
A software company is developing a new product and wants to release it to market quickly. The product will handle payment card data and must comply with PCI DSS. The team is considering using a DevOps approach with continuous deployment. Which practice best ensures that PCI DSS requirements are met while maintaining the speed of continuous deployment?
Select an answer first - 14
Which security practice is most directly associated with the deployment phase of a secure SDLC?
Select an answer first - 15
A security team is reviewing the SDLC of a new application. They want to ensure that security is considered at every phase, not just at the end. Which approach best achieves this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.