
Certified Secure Software Lifecycle Professional
Domain 4Objective 7
Define Secure Operational Architecture (e.g., Deployment Topology, Operational Interfaces, Continuous Integration and Continuous Delivery (CI/CD)) CSSLP Practice Questions (Page 1)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
15%of the exam
Questions 1–5
- 1
A company is designing a disaster recovery plan for its multi-tier application. The security architect must ensure that the environment can be recovered quickly after a security incident while maintaining forensic integrity. Which design should be implemented?
Select an answer first - 2
What is the primary purpose of a security baseline in secure configuration management?
Select an answer first - 3
Why is change control important in secure configuration management?
Select an answer first - 4
In a microservices deployment topology, which security challenge is most prominent compared to a monolithic application?
Select an answer first - 5
A financial services company exposes a set of REST APIs to third-party partners. The security architect must protect these operational interfaces while allowing partners to integrate with the system. Which control should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.