
Certified Secure Software Lifecycle Professional
Domain 2Objective 5
Define Security Metrics (e.g., Criticality Level, Average Remediation Time, Complexity, Key Performance Indicators (KPI), Objectives and Key Results) CSSLP Practice Questions (Page 2)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
11%of the exam
Questions 6–10
- 6
What does the average remediation time metric primarily measure?
Select an answer first - 7
A team fixed 10 security issues in a month. The time to fix each issue (in days) was: 2, 3, 5, 7, 1, 4, 6, 8, 2, 3. What is the average remediation time?
Select an answer first - 8
A security team wants to measure the effectiveness of its vulnerability remediation process. They have data showing that critical vulnerabilities are fixed in an average of 5 days, high in 10 days, and medium in 20 days. They also track the percentage of critical vulnerabilities fixed within the SLA of 7 days, which is currently 85%. Which metric best indicates whether the team is meeting its remediation SLAs for the most important vulnerabilities?
Select an answer first - 9
How is 'complexity' used as a security metric?
Select an answer first - 10
In the context of security metrics, what does 'criticality level' help an organization determine?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.