
Certified Secure Software Lifecycle Professional
Domain 3Objective 6
Develop Misuse and Abuse CSSLP Practice Questions (Page 1)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
1concept
13%of the exam
Questions 1–5
- 1
A financial application allows users to initiate wire transfers. The threat modeling session identified a misuse case: an authenticated user could submit a transfer request and then rapidly submit the same request multiple times before the first transaction completes, causing duplicate transfers. Which mitigating control directly addresses this specific abuse case?
Select an answer first - 2
A multi-tenant SaaS platform allows tenants to define custom email templates. The threat model identified a misuse case where a tenant injects malicious JavaScript into a template, which is then rendered in the admin panel of other tenants, causing stored XSS. The team must choose a control that prevents the XSS while still allowing tenants to use basic HTML formatting. Which control is most appropriate?
Select an answer first - 3
During a threat modeling session, a misuse case is identified where an authenticated user can escalate privileges by tampering with a hidden form field. Which mitigating control directly addresses this specific risk?
Select an answer first - 4
A government portal allows citizens to file tax returns online. The threat model identified a misuse case where an attacker submits a crafted XML payload to the backend parser, exploiting an external entity to read local files. The team needs a control that neutralizes this specific vulnerability class. Which control should be specified?
Select an answer first - 5
A SaaS application allows tenants to upload CSV files for bulk data import. The threat model identified a misuse case where a tenant uploads a CSV containing formulas (e.g., =CMD|'/C calc'!A0) that, when exported and opened in a spreadsheet application, executes arbitrary commands on the analyst's workstation. Which mitigating control should be implemented?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.