
Certified Secure Software Lifecycle Professional
Domain 2Objective 5
Define Security Metrics (e.g., Criticality Level, Average Remediation Time, Complexity, Key Performance Indicators (KPI), Objectives and Key Results) CSSLP Practice Questions (Page 3)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
11%of the exam
Questions 11–15
- 11
A security team wants to improve its remediation process. They have been tracking the average remediation time for critical vulnerabilities, which is currently 10 days. They want to reduce it to 5 days. Which KPI would best track progress toward this goal?
Select an answer first - 12
A security manager wants to communicate the value of the security program to executives. They have data on the number of vulnerabilities found, the average remediation time, and the percentage of code reviewed. Which approach best demonstrates the effectiveness of the security program?
Select an answer first - 13
Which of the following best illustrates the role of security metrics in the software lifecycle?
Select an answer first - 14
Which of the following is an example of a KPI for a secure software lifecycle?
Select an answer first - 15
Which of the following correctly pairs an objective with a key result in an OKR for security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.