
Certified Secure Software Lifecycle Professional
Domain 6Objective 1
Develop Security Testing Strategy & Plan CSSLP Practice Questions (Page 2)
Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
14%of the exam
Questions 6–10
- 6
A tester has full access to the source code, architecture diagrams, and internal documentation of an application. The goal is to perform a thorough review of the code to identify security flaws. Which testing technique is being used?
Select an answer first - 7
A security team is testing a new web application. They have access to the source code and are also conducting black-box testing to simulate an external attacker. The team wants to ensure that the application's authentication mechanism is robust against both known and unknown vulnerabilities. Which combination of testing techniques is most appropriate?
Select an answer first - 8
Which security testing standard is primarily focused on providing a structured methodology for testing the security of software applications, including specific test cases and techniques?
Select an answer first - 9
A security tester is asked to verify that the application can handle a sudden increase in user load without crashing or degrading performance. Which type of testing is being described?
Select an answer first - 10
A security manager is selecting a framework to guide the organization's security testing strategy. Which standard is specifically designed to assess and improve the maturity of an organization's software security processes?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.