
Certified Secure Software Lifecycle Professional
Domain 3Objective 1
Define Software Security Requirements CSSLP Practice Questions (Page 3)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
13%of the exam
Questions 11–15
- 11
A software company is developing a new mobile banking app. The security team has identified several potential requirements: (1) mandatory multi-factor authentication for all transactions, (2) end-to-end encryption for all data, (3) real-time fraud detection, and (4) biometric login for convenience. The project has a tight budget and a 6-month deadline. The product owner wants to maximize security while staying within constraints. Which requirement should be prioritized first?
Select an answer first - 12
A software team is developing a new online payment system. They have identified several security requirements: (A) PCI-DSS compliance, (B) two-factor authentication for admin accounts, (C) real-time fraud monitoring, and (D) a user-friendly password reset process. The project has limited resources and must deliver in 3 months. Which requirement should be deprioritized to focus on the most critical security controls?
Select an answer first - 13
A software company is developing a new mobile app for booking travel. The security team has identified several requirements: (A) the app must use OAuth 2.0 for third-party logins, (B) the app must store user credentials securely, (C) the app must have a user-friendly interface, and (D) the app must comply with GDPR for European users. The project has a limited budget. Which requirement should be prioritized to address the most significant security risk?
Select an answer first - 14
A development team is documenting security requirements for an e-commerce platform. They need to ensure that each requirement can be traced from the original business need through design, testing, and deployment. Which documentation practice best supports traceability?
Select an answer first - 15
A security analyst is eliciting requirements for a financial application. Which source is most relevant for identifying regulatory security requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.