Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 6Objective 2

Develop Security Test Cases CSSLP Practice Questions (Page 1)

Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
12concepts
14%of the exam

Questions 1–5

  1. 1expert · hard

    A security team is validating the attack surface of a new IoT device management platform. The platform includes a web console, a mobile app API, and a device firmware update mechanism. The team has limited time and resources and must prioritize testing. Which entry point should be tested first, given that a compromise could allow an attacker to push malicious firmware to all devices?

    Select an answer first
  2. 2application · medium

    A developer is writing a fuzzing test for a file upload feature that accepts PDF files. The test should generate malformed PDFs by mutating valid files and also create completely random data to send to the upload endpoint. Which approach best implements this fuzzing strategy?

    Select an answer first
  3. 3foundation · easy

    A development team integrates security tests into their CI/CD pipeline so that every code commit triggers automated security checks. This practice is best described as:

    Select an answer first
  4. 4application · medium

    A developer is writing unit tests for a new input validation function. The function is used to sanitize user input before it is stored in a database. The developer wants to ensure that the tests cover all branches of the function, including error handling for invalid input types. Which approach best achieves this?

    Select an answer first
  5. 5application · medium

    A security tester is developing test cases for a new online banking application. The tester wants to simulate a user attempting to transfer funds to an account they don't own, and also simulate a user trying to access another user's account by manipulating the session ID. Which testing approach best covers these scenarios?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.