
Certified Secure Software Lifecycle Professional
Domain 2Objective 5
Define Security Metrics (e.g., Criticality Level, Average Remediation Time, Complexity, Key Performance Indicators (KPI), Objectives and Key Results) CSSLP Practice Questions (Page 4)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
11%of the exam
Questions 16–20
- 16
A development organization wants to improve its secure coding practices. They set a goal to 'Reduce the number of security defects introduced during development.' They define a key result as 'Decrease the number of security defects found in code review per 1,000 lines of code by 20% within the next two quarters.' Which aspect of this OKR is the key result?
Select an answer first - 17
A security team is prioritizing vulnerabilities for remediation. They have two vulnerabilities: one in a customer-facing web application with a known exploit and a CVSS score of 9.0, and one in an internal tool with no known exploit and a CVSS score of 7.5. The team has limited resources and can only fix one this week. Which vulnerability should be prioritized?
Select an answer first - 18
What is the primary purpose of security metrics in a secure software lifecycle?
Select an answer first - 19
What is a Key Performance Indicator (KPI) in the context of secure software development?
Select an answer first - 20
A security manager wants to track the effectiveness of the security awareness training program for developers. Which KPI would best measure the reduction in security mistakes in code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.