
Certified Secure Software Lifecycle Professional
Domain 3Objective 1
Define Software Security Requirements CSSLP Practice Questions (Page 1)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
13%of the exam
Questions 1–5
- 1
A development team is documenting security requirements for a new online voting system. They need to ensure that the requirements are clear and can be validated by testers. Which documentation approach is most effective?
Select an answer first - 2
A product owner provides the user story: 'As a customer, I want to reset my password so I can regain access to my account.' Which of the following is a functional security requirement derived from this story?
Select an answer first - 3
During security requirements elicitation for a new e-commerce platform, which activity is most directly part of eliciting security requirements?
Select an answer first - 4
A government agency is developing a public-facing permit application system. During requirements elicitation, stakeholders include citizens, agency staff, and legal counsel. The legal counsel emphasizes compliance with data protection laws, while citizens express concerns about privacy. The agency wants to ensure comprehensive security coverage. Which approach best supports comprehensive security requirements elicitation?
Select an answer first - 5
A financial institution is developing a new online banking platform. The platform must support high transaction volumes during peak hours and maintain security. The security team is defining non-functional requirements. They are considering: (A) the system must encrypt all data in transit, (B) the system must have a maximum latency of 500ms for transactions, (C) the system must log all access attempts, and (D) the system must be able to scale horizontally during peak loads. Which two requirements are non-functional security requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.