
Certified Cloud Security Professional
Domain 4Objective 2
Describe the Secure Software Development Life Cycle (SDLC) Process CCSP Practice Questions (Page 4)
Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
4concepts
16%of the exam
Questions 16–20
- 16
A healthcare startup is developing a patient portal that will handle protected health information (PHI). The product owner has defined functional requirements for appointment scheduling and prescription refills, but has not yet considered how the system should handle data encryption, audit logging, or uptime during peak usage. As the security architect, which action best aligns security objectives with business goals during the requirements phase?
Select an answer first - 17
A security team is conducting a threat model for a new web application. The application will allow users to upload files, which will be stored and shared with other users. The team has identified that the application is vulnerable to malicious file uploads. Which mitigation is most effective to implement during the design phase?
Select an answer first - 18
Which security activity is most commonly associated with the development phase of a secure SDLC?
Select an answer first - 19
A development team is using a continuous integration/continuous deployment (CI/CD) pipeline to deploy a new application. The security team has identified that the application is vulnerable to SQL injection. The team wants to fix the vulnerability and prevent it from recurring. Which combination of activities is most effective?
Select an answer first - 20
A startup is developing a mobile app that will collect user location data. The business wants to monetize the data by sharing it with third-party advertisers. The legal team has raised concerns about privacy regulations. Which approach best aligns security and business goals?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.