Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 3Objective 6

Develop Misuse and Abuse CSSLP Practice Questions (Page 4)

Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
1concept
13%of the exam

Questions 16–20

  1. 16application · medium

    A content management system allows authors to upload images. The threat model identified a misuse case where an author uploads a file with a .html extension disguised as an image, which is then served to other users, enabling stored XSS. The team needs a control that prevents the file from being interpreted as active content. Which control is most effective?

    Select an answer first
  2. 17expert · hard

    A cloud-native application uses AWS Lambda functions to process user-uploaded images. The threat model identified a misuse case where a user uploads a malicious image that exploits a vulnerability in the image-processing library, allowing arbitrary code execution in the Lambda environment. The team must select a control that minimizes the blast radius of this attack. Which control is most appropriate?

    Select an answer first
  3. 18expert · hard

    A web application allows users to upload profile pictures. The team identified a misuse case where an attacker uploads a polyglot file that is both a valid image and a valid HTML page, leading to stored XSS when the file is served. The team must select a control that prevents the file from being rendered as HTML while still allowing the image to be displayed. Which control is most appropriate?

    Select an answer first
  4. 19application · medium

    A mobile banking app allows users to reset their password via SMS. The threat model identified a misuse case where an attacker performs SIM swapping to intercept the OTP and take over the account. The team must select a mitigating control that reduces the risk of this specific attack. Which control is most appropriate?

    Select an answer first
  5. 20expert · hard

    A company's internal tool uses a shared service account to access a third-party API. The threat model identified a misuse case where a developer exfiltrates the API key from the source code and uses it to make unauthorized calls, incurring high costs. The team must select a control that prevents the key from being exposed in source code while allowing the application to authenticate. Which control is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSSLP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.