
Certified Secure Software Lifecycle Professional
Domain 4Objective 3
Evaluate and Select Reusable Technologies CSSLP Practice Questions (Page 2)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)
36questions here
8free pages
10concepts
15%of the exam
Questions 6–10
- 6
A development team wants to deploy a microservices-based application where each service runs in an isolated user space with its own filesystem and network stack, but they want to avoid the overhead of managing separate operating systems. They also need to ensure that the deployment configuration is version-controlled and reproducible. Which combination of technologies should they choose?
Select an answer first - 7
What is the primary purpose of a Trusted Platform Module (TPM)?
Select an answer first - 8
Which operating system control is used to enforce mandatory access control (MAC) policies?
Select an answer first - 9
What is the primary goal of Data Loss Prevention (DLP) systems?
Select an answer first - 10
A financial application must prevent clients from directly reaching internal database servers. The security team wants a control that can inspect application-layer traffic, enforce allowlisting of specific SQL commands, and terminate TLS connections for centralized logging. Which technology should be placed between the clients and the database servers?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.