
Certified Secure Software Lifecycle Professional
Domain 6Objective 1
Develop Security Testing Strategy & Plan CSSLP Practice Questions (Page 5)
Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
6concepts
14%of the exam
Questions 21–24
- 21
When setting up a testing environment, a tester must ensure that the application can communicate with external systems it will interact with in production. Which consideration is being addressed?
Select an answer first - 22
A company wants to launch a bug bounty program to complement its internal testing. The security team is defining the scope and rules. Which practice is most important for the program to be effective and manageable?
Select an answer first - 23
A security team is testing a new authentication service. They need to verify that the service correctly enforces password policies and also that it can handle a high volume of login attempts. The team has limited time and resources. Which approach is most appropriate?
Select an answer first - 24
An organization wants to encourage external security researchers to find and report vulnerabilities in its software. Which program is specifically designed for this purpose?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.