
Certified Secure Software Lifecycle Professional
Domain 8Objective 2
Analyze Security of Third-Party Software CSSLP Practice Questions (Page 3)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
3concepts
10%of the exam
Questions 11–15
- 11
A security analyst is reviewing a third-party vendor's cloud controls matrix (CCM) and notices that the 'Incident Response' control states 'The vendor will notify customers of a security incident within 72 hours of discovery.' The vendor's SOC 2 Type II report includes a control description for incident response but does not specify a notification timeframe. The analyst's organization requires notification within 24 hours. What should the analyst do?
Select an answer first - 12
A third-party software vendor claims to have achieved SOC 2 Type II certification. Which statement best describes what this certification attests to?
Select an answer first - 13
A company is evaluating a third-party identity provider (IdP) that will be integrated into its customer-facing application. The vendor's cloud controls matrix (CCM) indicates that multi-factor authentication (MFA) is 'available' for customer accounts. The vendor's SOC 2 Type II report includes a control description stating that MFA is 'offered as an optional feature' but does not describe any testing of MFA enforcement. The company's security policy requires MFA to be enforced for all customer accounts. What should the company do?
Select an answer first - 14
A government contractor is evaluating a cloud-based document management system that will handle controlled unclassified information (CUI). The vendor holds FedRAMP Moderate authorization. The contractor's security team also sees that the vendor has ISO 27001 certification and a SOC 2 Type II report. Which certification or authorization is most directly relevant to the contractor's requirement to handle CUI?
Select an answer first - 15
Which third-party security certification or attestation is specifically designed for cloud service providers to demonstrate compliance with U.S. federal government security requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.