
Certified Secure Software Lifecycle Professional
Domain 5Objective 5
Evaluate and Integrate Components CSSLP Practice Questions (Page 2)
Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
5concepts
14%of the exam
Questions 6–10
- 6
Which element is typically included in a trust contract between integrated systems?
Select an answer first - 7
A company's application uses several open-source components. The security team wants to identify known vulnerabilities and license risks in these components. Which tool or practice is most appropriate?
Select an answer first - 8
A development team is integrating a third-party component that is no longer maintained by its original developer. The component has a known vulnerability. What is the most appropriate action?
Select an answer first - 9
What is a key security consideration when integrating third-party code with a restrictive open-source license?
Select an answer first - 10
In a systems-of-systems context, what is the primary purpose of a trust contract between two integrated systems?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.