
Certified Secure Software Lifecycle Professional
Domain 3Objective 8
Define Third-Party Vendor Security Requirements CSSLP Practice Questions (Page 3)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
13%of the exam
Questions 11–15
- 11
A multinational corporation is integrating a third-party customer relationship management (CRM) system that will store personal data of customers in multiple jurisdictions. The corporation's security team must assess the vendor's risk, but the vendor has different security certifications for different regions. The compliance team requires that data residency be maintained within specific countries. What is the most comprehensive approach to this vendor risk assessment?
Select an answer first - 12
A company has a long-term contract with a vendor that provides a critical software component. The vendor's security posture has been stable, but the company's security team is concerned about the vendor's recent acquisition by another company. The acquisition may change the vendor's security policies and personnel. What is the most appropriate action for ongoing vendor monitoring?
Select an answer first - 13
When defining security requirements for a third-party vendor, what is the most important characteristic of these requirements?
Select an answer first - 14
A company is evaluating a vendor that will provide a critical component of its software supply chain. The vendor has passed a security questionnaire, but the company's security team has limited resources and cannot conduct a full on-site audit. The vendor is located in a different country, and the company has no prior relationship with them. What is the most effective due diligence approach given these constraints?
Select an answer first - 15
During the requirements phase for a new software system, the organization plans to integrate a third-party authentication service. What is the primary purpose of performing a third-party vendor risk assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.