
Certified Secure Software Lifecycle Professional
Domain 3Objective 6
Develop Misuse and Abuse CSSLP Practice Questions (Page 2)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
1concept
13%of the exam
Questions 6–10
- 6
A DevOps platform provides a webhook feature that sends HTTP POST requests to user-specified URLs. The threat model identified a misuse case where a user configures a webhook to point to an internal IP address (e.g., 169.254.169.254) to access cloud metadata and steal credentials. Which mitigating control is most effective?
Select an answer first - 7
A misuse case describes an attacker exploiting a file upload feature to place a malicious executable on the server. Which mitigating control is most directly aligned with this abuse case?
Select an answer first - 8
An e-commerce platform is adding a 'remember me' feature. The team identified a misuse case where an attacker with temporary physical access to a logged-in user's device could use the persistent cookie to access the account after the user leaves. The product owner wants to balance usability with security. Which mitigating control should be specified?
Select an answer first - 9
A healthcare SaaS provider is designing a patient portal. The team identified a misuse case where an authenticated patient could tamper with URL parameters to view another patient's medical records (IDOR). The development team wants a control that is effective regardless of how the client constructs requests. Which mitigating control should the security lead specify?
Select an answer first - 10
A healthcare application allows patients to book appointments. The team identified a misuse case where an attacker performs a denial-of-service attack by submitting hundreds of appointment requests in a short period, exhausting the booking system's resources. The system must remain available for legitimate users during the attack. Which mitigating control is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.