
Certified Secure Software Lifecycle Professional
Domain 3Objective 7
Develop Security Requirement Traceability Matrix CSSLP Practice Questions (Page 1)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
9concepts
13%of the exam
Questions 1–5
- 1
What should be done to the traceability matrix when a security requirement is changed?
Select an answer first - 2
A development team is using a version control system for code and a test management tool for test cases. They want to automate the traceability between security requirements and test cases. What is the most effective approach?
Select an answer first - 3
A security requirement is removed from the project scope after a risk assessment. The traceability matrix must be updated. What is the correct action?
Select an answer first - 4
When creating traceability links, which of the following is a best practice?
Select an answer first - 5
An organization is preparing for a security audit. The auditor requires evidence that all security requirements are implemented and tested. The organization has a traceability matrix, but it is incomplete. What is the best course of action?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.