Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 3Objective 1

Define Software Security Requirements CSSLP Practice Questions (Page 4)

Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
5concepts
13%of the exam

Questions 16–20

  1. 16application · medium

    A development team is writing security requirements for a new customer relationship management (CRM) system. They want to ensure that each requirement is verifiable. Which requirement statement is the most testable?

    Select an answer first
  2. 17expert · hard

    A healthcare organization is developing a patient portal that will integrate with third-party fitness devices. The integration will allow patients to share health data with their doctors. The security team is eliciting requirements. They have identified the following: (A) secure API authentication, (B) patient consent management, (C) data minimization, and (D) real-time data synchronization. The organization has limited development resources and must prioritize. Which requirement is most critical to address first?

    Select an answer first
  3. 18expert · hard

    A company is developing a new remote work platform that includes video conferencing and file sharing. The security team has identified several requirements: (A) end-to-end encryption for video calls, (B) multi-factor authentication for all users, (C) data loss prevention (DLP) for shared files, and (D) a user-friendly interface. The company has a limited budget and must prioritize. Which requirement should be prioritized to address the most critical security risk?

    Select an answer first
  4. 19application · medium

    A healthcare startup is building a patient portal that allows users to book appointments and view lab results. During requirements elicitation, the product owner states that 'users must be able to log in securely.' The compliance team adds that the portal must meet HIPAA requirements for protecting health information. The development team needs a clear, testable requirement. Which requirement statement best translates the business need into a functional security requirement?

    Select an answer first
  5. 20application · medium

    A company is developing a new employee self-service portal. The portal will allow employees to update their personal information and view pay stubs. The security team is defining functional security requirements. Which requirement is a functional security requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.