
Certified Secure Software Lifecycle Professional
Domain 2Objective 5
Define Security Metrics (e.g., Criticality Level, Average Remediation Time, Complexity, Key Performance Indicators (KPI), Objectives and Key Results) CSSLP Practice Questions (Page 1)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
11%of the exam
Questions 1–5
- 1
A security team wants to set a goal to improve the security of the software development lifecycle. They decide to use OKRs. Which of the following is a well-formed key result for the objective 'Improve the security of the software development lifecycle'?
Select an answer first - 2
What is the purpose of using Objectives and Key Results (OKRs) in a secure software lifecycle?
Select an answer first - 3
Which scenario best demonstrates the use of complexity as a security metric?
Select an answer first - 4
A security analyst is evaluating two vulnerabilities. Vulnerability A can be exploited with a simple script that is publicly available, while Vulnerability B requires a custom exploit that has not been published. Which vulnerability has higher complexity?
Select an answer first - 5
What does the criticality level of a vulnerability indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.