Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 6Objective 5

Analyze Security Implications of Test Results (e.g., Impact on Product Management, Prioritization, Break/build Criteria) CSSLP Practice Questions (Page 2)

Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
4concepts
14%of the exam

Questions 6–10

  1. 6foundation · easy

    Two vulnerabilities are found: one has a high CVSS score but affects a low-value internal tool, and another has a medium CVSS score but affects a customer-facing payment system. According to risk-based prioritization, which should be addressed first?

    Select an answer first
  2. 7foundation · easy

    A security test report reveals a critical vulnerability in a feature scheduled for the next release. According to secure software lifecycle principles, what is the primary impact on product management?

    Select an answer first
  3. 8application · medium

    A security test report contains a finding that is rated 'Medium' severity but affects a feature that is critical to a major client's workflow. The client is unaware of the issue. The product manager wants to inform the client, but the development lead argues that the issue is not severe enough to warrant client communication. As the security lead, what should you advise?

    Select an answer first
  4. 9application · medium

    A security test report includes a critical vulnerability in a customer-facing application. The company's legal team is concerned about potential regulatory implications. The product manager wants to know if the release should be delayed. How should the security lead communicate the findings to the legal team?

    Select an answer first
  5. 10application · medium

    After a penetration test, you need to communicate the results to the executive team. The report includes a critical remote code execution vulnerability in a customer-facing API and several low-risk findings. The executives are not technical and are concerned about the impact on the upcoming product launch. How should you present the findings?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.