
Certified Secure Software Lifecycle Professional
Domain 8Objective 2
Analyze Security of Third-Party Software CSSLP Practice Questions (Page 4)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
3concepts
10%of the exam
Questions 16–20
- 16
A multinational corporation is evaluating a cloud-based HR platform that will store employee data for operations in the EU and the US. The vendor holds ISO 27001 and SOC 2 Type II, and provides a cloud controls matrix (CCM) showing data residency options in both regions. The EU legal team requires that personal data of EU employees remain within the EU. The US team wants the lowest-latency access for US-based administrators. What is the most appropriate course of action?
Select an answer first - 17
What is the primary purpose of a cloud controls matrix (CCM) when evaluating a third-party cloud service provider?
Select an answer first - 18
A financial services firm is selecting a third-party payment processing library. Vendor A holds SOC 2 Type II and has a strong public track record, but its last release was 18 months ago and its support forum shows unanswered security questions. Vendor B has no formal certification but releases patches monthly and responds to security advisories within 24 hours. The firm's policy requires documented security assurance for all critical third-party components. What should the firm do?
Select an answer first - 19
A security analyst is reviewing a third-party SaaS vendor's cloud controls matrix (CCM) to verify that the vendor encrypts data at rest. The CCM lists 'AES-256 encryption for data at rest' under the 'Data Encryption' control. However, the vendor's SOC 2 Type II report does not mention encryption at rest in its control descriptions or testing procedures. What is the most appropriate conclusion?
Select an answer first - 20
A healthcare SaaS provider is being evaluated for a system that will process protected health information (PHI) for a US-based hospital. The vendor holds both SOC 2 Type II and ISO 27001 certifications, but the hospital's compliance team insists on a FedRAMP authorization. The vendor explains they have not pursued FedRAMP because they do not serve government agencies. Which statement best describes the compliance team's requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.