
Certified Secure Software Lifecycle Professional
Domain 5Objective 1
Adhere to Relevant Secure Coding Practices (e.g., Standards, Guidelines, Regulations) CSSLP Practice Questions (Page 2)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
15concepts
14%of the exam
Questions 6–10
- 6
A startup is building a mobile payment app and wants to use an open-source cryptography library to handle encryption. The library is popular but has not had a release in 18 months. The team's security lead is concerned about supply-chain risk. The team has limited time and must integrate the library this sprint. Which action best balances security risk with the delivery constraint?
Select an answer first - 7
A development team is building a .NET web API for a government agency. The security team requires that all endpoints enforce authentication and that role-based authorization be applied consistently. The team wants to minimize the risk of a developer forgetting to add an authorization check to a new endpoint. Which approach best meets this requirement?
Select an answer first - 8
Which cryptographic algorithm is considered secure for encrypting data at rest?
Select an answer first - 9
A web application allows users to stay logged in across browser restarts. The session cookie is currently set without an expiration time, so it is a session cookie. Users are complaining that they are logged out every time they close the browser. The team wants to implement persistent sessions securely. Which approach should they take?
Select an answer first - 10
A document management system needs to allow users to share files with specific colleagues. The system currently uses a single role-based access control (RBAC) model where users are assigned roles like 'Editor' and 'Viewer'. The product owner wants users to be able to grant access to individual files to other users. Which approach should the team implement to satisfy this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.