
Certified Secure Software Lifecycle Professional
Domain 2Objective 5
Define Security Metrics (e.g., Criticality Level, Average Remediation Time, Complexity, Key Performance Indicators (KPI), Objectives and Key Results) CSSLP Practice Questions (Page 5)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
6concepts
11%of the exam
Questions 21–23
- 21
A security team tracks the time taken to fix vulnerabilities. In the last month, they fixed 10 vulnerabilities with the following remediation times in days: 2, 3, 3, 4, 5, 5, 6, 7, 8, 30. The 30-day fix was for a complex legacy system. Which metric would be most misleading if used to report the team's typical remediation performance?
Select an answer first - 22
A security team is trying to demonstrate the effectiveness of its secure software lifecycle to management. They have data on the number of vulnerabilities found in each phase (design, coding, testing, production) and the average remediation time for each phase. Which metric would best demonstrate the value of shifting security left?
Select an answer first - 23
A security team is prioritizing vulnerabilities for remediation. They have two vulnerabilities: one in a critical business application that is not internet-facing, and one in a non-critical internal tool that is internet-facing. The vulnerability in the critical application has a CVSS score of 6.0, while the vulnerability in the internal tool has a CVSS score of 8.0. Which vulnerability should be prioritized?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.