
Certified Secure Software Lifecycle Professional
Domain 3Objective 7
Develop Security Requirement Traceability Matrix CSSLP Practice Questions (Page 3)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
9concepts
13%of the exam
Questions 11–15
- 11
A risk analyst is using the traceability matrix to assess whether a newly identified threat is adequately mitigated. The threat is 'SQL injection via user input fields'. The analyst wants to find which security requirements address this threat and whether they are implemented and tested. What should the analyst do?
Select an answer first - 12
What does a coverage analysis of the traceability matrix primarily identify?
Select an answer first - 13
What role does the traceability matrix play in demonstrating compliance with security standards?
Select an answer first - 14
A security team is using a requirements management tool that supports traceability, but they are not using it effectively. The team is manually updating a spreadsheet and often misses links. They want to improve the process with minimal disruption. What is the best approach?
Select an answer first - 15
How does the traceability matrix support compliance audits?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.