
Certified Secure Software Lifecycle Professional
Domain 5Objective 4
Address the Identified Security Risks (e.g., Risk Strategy) CSSLP Practice Questions (Page 2)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
14%of the exam
Questions 6–10
- 6
After applying mitigation controls, a risk remains that is within the organization's acceptable threshold. What should be done with this risk?
Select an answer first - 7
What is the primary purpose of documenting residual risks in the risk register?
Select an answer first - 8
Which of the following is an example of a risk acceptance criterion?
Select an answer first - 9
A project has a residual risk of a data breach due to a third-party API. The risk owner has accepted the risk, but the organization's risk tolerance is low. The security team believes that the residual risk is still too high. Which action is most appropriate?
Select an answer first - 10
A large enterprise is developing a customer relationship management (CRM) system. The risk assessment identifies a high risk of data exfiltration via a third-party analytics SDK. The SDK is critical for business intelligence, and the marketing department strongly opposes removing it. The security team has limited budget for additional controls. Which strategy best balances the need for analytics with the security risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.