
Certified Secure Software Lifecycle Professional
Domain 6Objective 6
Classify and Track Security Errors CSSLP Practice Questions (Page 2)
Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
14%of the exam
Questions 6–10
- 6
A security manager is implementing a risk-scoring model for a software product. The product is a mobile app that stores user data in the cloud. The manager is debating whether to include 'data sensitivity' as a factor in the 'Impact' score. Why is it important to include this factor?
Select an answer first - 7
A security analyst is calculating the CVSS v3.1 score for a vulnerability. The vulnerability is in a library that is used by a critical internal application and a public-facing marketing website. The analyst calculates a base score of 7.5. The internal application is on a segmented network, while the marketing website is directly internet-facing. How should the analyst use this information to prioritize the remediation?
Select an answer first - 8
In the Common Vulnerability Scoring System (CVSS), what does the base score primarily reflect?
Select an answer first - 9
Which of the following is a common feature of security bug tracking tools that helps teams prioritize which vulnerabilities to fix first?
Select an answer first - 10
In a typical security bug tracking process, which step immediately follows the initial discovery and logging of a security bug?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.