Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 5Objective 5

Evaluate and Integrate Components CSSLP Practice Questions (Page 3)

Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)

21questions here
5free pages
5concepts
14%of the exam

Questions 11–15

  1. 11expert · hard

    A government agency integrates a new citizen-facing portal with an existing identity management system. The portal will handle sensitive personal data. The agency must validate the security of the integration before launch. Which testing approach is most comprehensive?

    Select an answer first
  2. 12expert · hard

    A manufacturing company integrates its production scheduling system with a supplier's inventory system. The integration uses a message queue. The security team is defining the trust contract. Which requirement is most important to include?

    Select an answer first
  3. 13application · medium

    A company's application uses a third-party library that is licensed under the GNU General Public License (GPL). The company's legal team is concerned about compliance. What is the primary risk associated with using GPL-licensed code?

    Select an answer first
  4. 14application · medium

    A development team is integrating an open-source library into their application. The library is popular and widely used. The team wants to ensure they are securely reusing this third-party code. Which practice is most important to implement?

    Select an answer first
  5. 15expert · hard

    A financial services firm is integrating a new analytics platform with its core banking system. The integration will share transaction data. The firm's security architect is performing a security analysis of the systems-of-systems. Which approach best identifies the attack surface and trust boundaries?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.