
Certified Secure Software Lifecycle Professional
Domain 5Objective 1
Adhere to Relevant Secure Coding Practices (e.g., Standards, Guidelines, Regulations) CSSLP Practice Questions (Page 3)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
15concepts
14%of the exam
Questions 11–15
- 11
What is cryptographic agility?
Select an answer first - 12
Which practice helps prevent session hijacking?
Select an answer first - 13
A web application allows users to log in and access their profile. A penetration test revealed that an attacker can force a victim's browser to send a request with a known session ID, allowing the attacker to impersonate the victim. The application currently accepts any session ID presented in the cookie. Which change should the team make to prevent this attack?
Select an answer first - 14
Why should credentials (e.g., API keys, passwords) not be hardcoded in source code?
Select an answer first - 15
A web application accepts a 'sort' parameter in the URL to order search results. The parameter is used directly in a SQL query. An attacker submits 'sort=name; DROP TABLE users;--' and the application executes the malicious SQL. Which control should the team implement to prevent this attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.