Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 8Objective 4

Ensure and Verify Supplier Security Requirements in the Acquisition Process CSSLP Practice Questions (Page 2)

Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 6–10

  1. 6foundation · easy

    Which factor is most important to specify in a contract regarding supplier log integration into the customer's SIEM?

    Select an answer first
  2. 7expert · hard

    Your organization is evaluating a supplier that has a strong security track record but has recently been acquired by a company with a poor security reputation. The supplier's current security team has remained in place, and they have assured you that their practices are unchanged. Your organization requires a high level of assurance for this critical component. What is the most prudent course of action?

    Select an answer first
  3. 8expert · hard

    Your organization is procuring a software-as-a-service (SaaS) product. The vendor is responsible for the security of the application and underlying infrastructure, but your organization is responsible for user access management and client-side security. During a security review, your team discovers that the vendor's penetration testing does not cover the application's API endpoints. What is the most appropriate action?

    Select an answer first
  4. 9application · medium

    Your organization is integrating a new supplier's logs into your SIEM. The supplier provides logs in a proprietary format that your SIEM cannot parse. Your team has limited resources to build a custom parser. What is the most efficient approach?

    Select an answer first
  5. 10application · medium

    Your organization is acquiring a software product from a supplier that has passed initial security questionnaires. During contract negotiations, the supplier refuses to allow your auditors to perform an on-site assessment of their development environment, citing confidentiality concerns. They offer to provide a summary of their security certifications instead. Your compliance team requires evidence that the supplier's secure coding practices are actually implemented. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.