
Certified Secure Software Lifecycle Professional
Domain 7Objective 8
Execute the Incident Response Plan CSSLP Practice Questions (Page 1)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)
33questions here
7free pages
7concepts
11%of the exam
Questions 1–5
- 1
After a security incident, the incident response team conducts a post-incident review. They find that the incident response plan was not followed because the on-call analyst was not trained on the plan. The team must decide how to address this finding. Which action is most appropriate?
Select an answer first - 2
During forensic analysis of a breach, an investigator finds that the attacker used a legitimate administrator account to access the system. The account belongs to an employee who is on vacation. The investigator must determine if the account was compromised or if the employee is involved. What is the most appropriate next step?
Select an answer first - 3
A financial services company detects a ransomware outbreak on a single file server. The incident response team is activated. The server hosts non-critical archived reports, but it is also connected to a network segment that contains the production database. The team must decide the immediate priority. What should the first action be?
Select an answer first - 4
A company's web application was defaced, and the incident response team has identified a vulnerability in the content management system as the entry point. The team needs to remediate the incident while minimizing business disruption. Which action should be part of the remediation plan?
Select an answer first - 5
A company's e-commerce website was compromised, and the attackers defaced the site and stole customer data. The incident response team has contained the breach and identified the vulnerability. The company must remediate the incident while minimizing revenue loss. Which remediation strategy is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.