Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 6Objective 2

Develop Security Test Cases CSSLP Practice Questions (Page 2)

Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
12concepts
14%of the exam

Questions 6–10

  1. 6expert · hard

    A team is preparing to test a microservices-based application in a staging environment that mirrors production. The test must validate security behavior under realistic load and data conditions, but the staging environment uses synthetic data that does not match production data patterns. The team wants to ensure the test results are representative. Which action best addresses this gap?

    Select an answer first
  2. 7foundation · easy

    A tester deliberately introduces faults, such as simulating a database outage or injecting errors, to verify that the application fails gracefully. This testing practice is called:

    Select an answer first
  3. 8expert · hard

    A security team is planning a penetration test for a critical financial application. The test must validate the effectiveness of the Web Application Firewall (WAF) and the authentication controls, but the test window is limited to 48 hours. The team has a full set of credentials for a standard user account and knows the application's entry points. Which testing strategy best balances coverage and time constraints?

    Select an answer first
  4. 9application · medium

    A developer is testing a new XML parser that will be used to process customer-supplied files. The developer wants to ensure the parser handles malformed XML gracefully and doesn't crash or expose sensitive information. Which testing technique is most appropriate?

    Select an answer first
  5. 10application · medium

    A company is integrating a new payment gateway into their existing e-commerce platform. The integration involves exchanging sensitive data between the two systems. The team wants to test the security of this integration before going live. Which testing approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.