Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 5Objective 4

Address the Identified Security Risks (e.g., Risk Strategy) CSSLP Practice Questions (Page 4)

Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)

27questions here
6free pages
6concepts
14%of the exam

Questions 16–20

  1. 16expert · hard

    A software project has a residual risk of a critical vulnerability in a legacy component. The risk owner wants to formally accept the risk, but the organization's risk tolerance is low. The security team has proposed a mitigation that would reduce the risk to an acceptable level but would delay the release by two weeks. The business is pressuring for an on-time release. Which action is most appropriate?

    Select an answer first
  2. 17application · medium

    A software team is designing a new file-sharing feature. The initial design requires users to upload files that are then processed by an external service. The risk assessment identifies that the external service has a history of data breaches. The team wants to eliminate this risk entirely. Which action best achieves risk avoidance?

    Select an answer first
  3. 18application · medium

    A development team is implementing a web application that handles user authentication. The risk assessment identified a risk of brute-force attacks on the login endpoint. The team is in the implementation phase. Which control best mitigates this risk?

    Select an answer first
  4. 19foundation · easy

    A company signs a contract with a cloud provider that includes a service-level agreement (SLA) with penalties for downtime. This is an example of:

    Select an answer first
  5. 20application · medium

    After implementing a series of security controls, a software project has a residual risk of a denial-of-service (DoS) attack. The risk owner must decide how to handle this residual risk. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.