
Certified Secure Software Lifecycle Professional
Domain 3Objective 6
Develop Misuse and Abuse CSSLP Practice Questions (Page 4)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
1concept
13%of the exam
Questions 16–20
- 16
A content management system allows authors to upload images. The threat model identified a misuse case where an author uploads a file with a .html extension disguised as an image, which is then served to other users, enabling stored XSS. The team needs a control that prevents the file from being interpreted as active content. Which control is most effective?
Select an answer first - 17
A cloud-native application uses AWS Lambda functions to process user-uploaded images. The threat model identified a misuse case where a user uploads a malicious image that exploits a vulnerability in the image-processing library, allowing arbitrary code execution in the Lambda environment. The team must select a control that minimizes the blast radius of this attack. Which control is most appropriate?
Select an answer first - 18
A web application allows users to upload profile pictures. The team identified a misuse case where an attacker uploads a polyglot file that is both a valid image and a valid HTML page, leading to stored XSS when the file is served. The team must select a control that prevents the file from being rendered as HTML while still allowing the image to be displayed. Which control is most appropriate?
Select an answer first - 19
A mobile banking app allows users to reset their password via SMS. The threat model identified a misuse case where an attacker performs SIM swapping to intercept the OTP and take over the account. The team must select a mitigating control that reduces the risk of this specific attack. Which control is most appropriate?
Select an answer first - 20
A company's internal tool uses a shared service account to access a third-party API. The threat model identified a misuse case where a developer exfiltrates the API key from the source code and uses it to make unauthorized calls, incurring high costs. The team must select a control that prevents the key from being exposed in source code while allowing the application to authenticate. Which control is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.