Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 5Objective 2

Analyze Code for Security Risks CSSLP Practice Questions (Page 1)

Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
14%of the exam

Questions 1–5

  1. 1expert · hard

    A development team is using a third-party library that has a known critical vulnerability. The library is widely used and no patched version is available. The team cannot remove the library because it is essential to the application. What is the best course of action?

    Select an answer first
  2. 2foundation · easy

    What is a logic bomb in software?

    Select an answer first
  3. 3application · medium

    A company is developing a new application and wants to reuse code from an internal library that was written for a previous project. The library has not been updated in several years and was not developed with security in mind. What should the team do?

    Select an answer first
  4. 4application · medium

    During a code review, a developer finds a block of code that is heavily obfuscated and contains a large amount of base64-encoded data. The code is not documented and is not part of the original requirements. What should the reviewer do?

    Select an answer first
  5. 5foundation · easy

    Why is manual code review still important even when SAST tools are used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.