Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 3Objective 8

Define Third-Party Vendor Security Requirements CSSLP Practice Questions (Page 5)

Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
5concepts
13%of the exam

Questions 21–25

  1. 21foundation · easy

    Which contractual clause is intended to hold a vendor financially responsible for damages resulting from a security breach?

    Select an answer first
  2. 22expert · hard

    A company is contracting with a vendor that will process sensitive financial data. The vendor has a history of minor security incidents but has always resolved them quickly. The company's legal team wants to include a clause that holds the vendor liable for any breach, but the vendor is resistant to unlimited liability. The company also wants to ensure ongoing monitoring of the vendor's security. What is the most balanced contractual approach?

    Select an answer first
  3. 23expert · hard

    A company is outsourcing its software testing to a vendor that will have access to production data. The company's security policy requires that all data be encrypted, and the compliance team requires that the vendor be able to demonstrate compliance with the company's security requirements. The vendor has proposed using its own encryption standards, which differ from the company's. What is the best way to define the vendor security requirements?

    Select an answer first
  4. 24foundation · easy

    Which activity is part of ongoing vendor management?

    Select an answer first
  5. 25application · medium

    A company has an existing contract with a vendor that provides customer support software. The vendor recently announced a change in their data storage location to a different country. The company's security team is concerned about the impact on data residency and compliance. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSSLP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.