Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 3Objective 8

Define Third-Party Vendor Security Requirements CSSLP Practice Questions (Page 4)

Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts
13%of the exam

Questions 16–20

  1. 16application · medium

    A financial services firm is engaging a cloud-based payroll provider. The firm's security policy requires encryption of all sensitive data both in transit and at rest, and mandates that the provider notify the firm within 24 hours of any security incident. The procurement team is drafting the contract. Which approach best defines the vendor security requirements?

    Select an answer first
  2. 17application · medium

    A healthcare organization is integrating a third-party analytics platform that will process de-identified patient data. The vendor's security questionnaire indicates they have SOC 2 Type II certification, but the organization's security team has not yet reviewed the actual report. The compliance officer insists on verifying the vendor's controls before signing. Which action best addresses the vendor risk assessment requirement?

    Select an answer first
  3. 18foundation · easy

    What is the primary purpose of conducting a vendor security assessment?

    Select an answer first
  4. 19application · medium

    A company is contracting with a vendor that will host a customer portal containing personal data. The company wants to ensure that the vendor's security controls are audited regularly and that any findings are shared with the company. Which contractual clause is most appropriate?

    Select an answer first
  5. 20foundation · easy

    An organization is considering a vendor that will provide a software component used in its customer-facing application. Which activity best exemplifies a third-party vendor risk assessment?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.