
Certified Secure Software Lifecycle Professional
Domain 6Objective 6
Classify and Track Security Errors CSSLP Practice Questions (Page 3)
Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
14%of the exam
Questions 11–15
- 11
A developer writes a line of code that incorrectly checks user input, allowing a buffer overflow. Which term best describes the developer's action that led to this flaw?
Select an answer first - 12
What is the primary purpose of documenting a security bug's lifecycle, from discovery to closure, in a bug tracking system?
Select an answer first - 13
A development team is using a risk-scoring matrix to prioritize security defects. The matrix scores 'Likelihood' from 1 (rare) to 5 (almost certain) and 'Impact' from 1 (negligible) to 5 (severe). A defect is found in a feature that is rarely used but, if exploited, could lead to a complete database compromise. The team rates the likelihood as 2 and the impact as 5. What is the risk score, and how should it be interpreted?
Select an answer first - 14
A QA tester finds that a user can access another user's profile by changing the ID in the URL. The tester logs this as a 'vulnerability'. A developer looks at the code and sees that the application is not checking if the logged-in user owns the profile. The developer fixes the code by adding an authorization check. In this scenario, what was the 'error'?
Select an answer first - 15
A security team is triaging a list of newly discovered vulnerabilities. They have a limited development capacity and can only fix a few issues in the next sprint. The team lead proposes using a risk-scoring model that multiplies the likelihood of exploitation by the potential business impact. Why is this approach more effective than simply prioritizing by the number of affected users?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.