Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 8Objective 4

Ensure and Verify Supplier Security Requirements in the Acquisition Process CSSLP Practice Questions (Page 1)

Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 1–5

  1. 1foundation · easy

    Which source of information is most reliable for assessing a supplier's historical security track record?

    Select an answer first
  2. 2application · medium

    A supplier has agreed to allow your organization to audit their secure software development practices. However, the supplier's development team uses an agile methodology with frequent releases, and your audit is scheduled for a single point in time. What is the best way to ensure the audit reflects the supplier's actual practices?

    Select an answer first
  3. 3expert · hard

    Your organization is choosing between two suppliers for a security-critical component. Supplier A offers a commercial license with a support contract that includes a 24-hour response time for critical vulnerabilities. Supplier B offers the same component under an open-source license with community support only. Your team has the expertise to handle security issues internally, but your compliance department requires a defined support structure for critical components. What is the most appropriate decision?

    Select an answer first
  4. 4application · medium

    Your organization is procuring a platform-as-a-service (PaaS) offering. The vendor is responsible for securing the underlying platform, but your team is responsible for the application code and its configuration. During a security review, you need to ensure that the vendor's security testing covers the platform layer. What is the best way to verify this?

    Select an answer first
  5. 5foundation · easy

    In a supplier engagement, what does the shared responsibility model primarily define?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.