
Certified Secure Software Lifecycle Professional
Domain 5Objective 4
Address the Identified Security Risks (e.g., Risk Strategy) CSSLP Practice Questions (Page 6)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
14%of the exam
Questions 26–27
- 26
A financial services firm is implementing a new customer portal. The risk assessment identified a high-severity vulnerability in a legacy authentication module that cannot be patched before the scheduled release. The business requires the portal to launch on time to meet a regulatory deadline. The security team must decide how to handle this risk. Which approach best aligns with the firm's constraints?
Select an answer first - 27
A company is developing a medical device software. The risk assessment identifies a risk of patient injury due to software malfunction. The company wants to reduce its financial liability while also ensuring patient safety. Which strategy best addresses both concerns?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.