Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 8Objective 4

Ensure and Verify Supplier Security Requirements in the Acquisition Process CSSLP Practice Questions (Page 3)

Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 11–15

  1. 11application · medium

    Your organization is evaluating two open-source libraries for a new application. Library A is community-maintained with frequent releases but no formal support. Library B is commercially backed with a paid support contract and a defined maintenance schedule. Your team has limited security expertise and requires timely assistance with vulnerability remediation. Which factor is most important in this decision?

    Select an answer first
  2. 12foundation · easy

    When a supplier provides a software component, which security testing activity is typically the customer's responsibility under the shared responsibility model?

    Select an answer first
  3. 13application · medium

    A software vendor you rely on for a critical component has just disclosed a vulnerability that affects your production environment. Your incident response team needs to understand the vendor's remediation timeline and whether they will provide a patch. Where should this information be defined to ensure a coordinated response?

    Select an answer first
  4. 14application · medium

    Your organization is procuring a cloud-based application from a vendor. The vendor provides the application and the underlying infrastructure, but your organization is responsible for configuring user access and managing client-side endpoints. During a security review, your team wants to ensure that the vendor's security testing covers the application layer. Which document should clearly define this responsibility?

    Select an answer first
  5. 15expert · hard

    A supplier with a generally good security track record has experienced a significant security incident. During the incident, the supplier failed to notify your organization within the contractual 24-hour window, and their initial report was incomplete. Your organization is now considering whether to renew the contract. What is the most balanced approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.