
Certified Secure Software Lifecycle Professional
Domain 3Objective 6
Develop Misuse and Abuse CSSLP Practice Questions (Page 3)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
1concept
13%of the exam
Questions 11–15
- 11
A legacy enterprise application uses a shared database account with a hardcoded password. The team identified a misuse case where a disgruntled employee with network access connects directly to the database and exfiltrates data. The security architect must select a mitigating control that reduces the risk without requiring a full application rewrite. Which control is most effective?
Select an answer first - 12
A fintech startup is building a payment API. The team identified two misuse cases: (1) an attacker replays a captured payment request to charge a customer twice, and (2) an attacker modifies the amount field in transit. The team must select a single control that mitigates both cases without requiring the client to maintain server-side state. Which control satisfies both requirements?
Select an answer first - 13
A collaboration tool supports real-time document editing. The team identified a misuse case where a malicious user sends a specially crafted message that causes the WebSocket connection to crash, denying service to other participants in the same document. Which mitigating control is most appropriate for this abuse case?
Select an answer first - 14
A mobile app allows users to log in with a PIN. The threat model identified a misuse case where an attacker with physical access to the device performs a brute-force attack by trying all possible PIN combinations. The team must select a control that prevents the attack while minimizing user friction. Which control is most appropriate?
Select an answer first - 15
A customer support application allows agents to search for customer records by name. The threat model identified a misuse case where an agent uses a wildcard search (e.g., '*') to retrieve and export the entire customer database. Which mitigating control is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.