
Certified Secure Software Lifecycle Professional
Domain 3Objective 1
Define Software Security Requirements CSSLP Practice Questions (Page 5)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
5concepts
13%of the exam
Questions 21–25
- 21
Which of the following is an example of a non-functional security requirement?
Select an answer first - 22
A company is developing a new social media platform. The platform will allow users to post content and interact with others. The security team is eliciting requirements. They have identified: (A) content moderation to prevent hate speech, (B) user authentication to prevent fake accounts, (C) data encryption to protect user privacy, and (D) real-time notifications for user engagement. The company has limited resources and must prioritize. Which requirement is most critical to address first?
Select an answer first - 23
What is a key characteristic of a well-documented security requirement?
Select an answer first - 24
When prioritizing security requirements, which factor should be considered to determine the order of implementation?
Select an answer first - 25
During requirements definition for a banking application, a stakeholder states: 'Users must be able to view their account balance after logging in.' Which translation best represents a functional security requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.