
Certified Secure Software Lifecycle Professional
Domain 5Objective 2
Analyze Code for Security Risks CSSLP Practice Questions (Page 5)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
14%of the exam
Questions 21–24
- 21
A development team is integrating a popular open-source library for image processing. The library was last updated 18 months ago and has a known critical vulnerability. The team wants to use it because it has features no other library provides. What should the team do first?
Select an answer first - 22
During a manual code review, a reviewer notices that a developer has added a hidden administrative account that is only activated when a specific environment variable is set. The code is not documented and the account bypasses normal authentication. What is the most likely security concern?
Select an answer first - 23
A developer wants to include a third-party library in a new project. Which action best aligns with secure code reuse practices?
Select an answer first - 24
Which resource is a community-developed list of the most critical web application security risks?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.