Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 8Objective 2

Analyze Security of Third-Party Software CSSLP Practice Questions (Page 2)

Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
3concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A company is evaluating a third-party email security gateway. The vendor holds a SOC 2 Type II report and an ISO 27001 certification. The company's compliance team is specifically concerned about the vendor's ability to protect data in transit. Which document should the compliance team review to find the most specific information about encryption controls?

    Select an answer first
  2. 7expert · hard

    A security architect is evaluating a third-party payment processing API. The vendor's cloud controls matrix (CCM) states that 'all data is encrypted in transit using TLS 1.2 or higher.' The vendor's SOC 2 Type II report includes a control description for encryption in transit and states that the auditor tested the control. However, the architect's organization requires TLS 1.3 for all internet-facing communications. The vendor's CCM does not mention TLS 1.3. What should the architect do?

    Select an answer first
  3. 8expert · hard

    A security architect is comparing two third-party cloud storage vendors. Vendor X provides a cloud controls matrix (CCM) that maps each control to a specific SOC 2 Type II control, and the SOC 2 report includes a 'complementary user entity controls' (CUECs) section. Vendor Y provides a CCM with similar controls but its SOC 2 report does not include a CUECs section. The architect's organization has strict internal requirements for key management and access reviews. Which consideration is most important when evaluating these vendors?

    Select an answer first
  4. 9application · medium

    A company is evaluating a third-party customer relationship management (CRM) vendor. The vendor holds ISO 27001 certification and provides a cloud controls matrix (CCM) that maps controls to ISO 27001 Annex A. The company's security team wants to verify that the vendor's access control policies are actually implemented. Which document or activity would provide the most direct evidence?

    Select an answer first
  5. 10application · medium

    A company is evaluating a commercial software vendor for a critical business application. The vendor is a small startup with a promising product but has been in business for only 18 months. The vendor's cloud controls matrix (CCM) lists strong security controls, and the vendor has provided a SOC 2 Type I report. The company's procurement team is concerned about the vendor's long-term viability. What is the most important additional factor to assess?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.