
Certified Secure Software Lifecycle Professional
Domain 5Objective 2
Analyze Code for Security Risks CSSLP Practice Questions (Page 2)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
14%of the exam
Questions 6–10
- 6
Which practice is most important when reusing an open-source component in a secure software development lifecycle?
Select an answer first - 7
Which technique is commonly used by SAST tools to identify coding flaws?
Select an answer first - 8
A security engineer is analyzing a suspicious binary and finds a section of code that is encrypted. The engineer suspects the code is a backdoor. What is the most effective way to analyze the encrypted code?
Select an answer first - 9
A security team is conducting a manual code review of a payment processing module. The reviewer finds that the code uses a weak hashing algorithm for storing passwords. What is the most appropriate recommendation?
Select an answer first - 10
A SAST tool flags a potential buffer overflow in a C++ application. The developer reviews the code and believes it is a false positive because the buffer size is checked before the operation. What should the developer do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.