
Certified Secure Software Lifecycle Professional
Domain 3Objective 2
Identify Compliance Requirements CSSLP Practice Questions (Page 4)
Part of the Secure Software Requirements domain, which accounts for 13% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
4concepts
13%of the exam
Questions 16–20
- 16
A company is developing a mobile payment app that will store credit card numbers and also collect health-related data for a wellness program. The app will be available in the EU and the United States. The security team is defining the compliance requirements. Which of the following is the most critical legal requirement to address?
Select an answer first - 17
A company is developing a new application and has a policy that all code must be reviewed by a security specialist. However, the project timeline is very tight, and the security team is overburdened. The project manager suggests skipping the review to meet the deadline. What is the most appropriate response?
Select an answer first - 18
A software company is developing a mobile health app that will be used by hospitals in the European Union to store patient records. The company is headquartered in the United States. Which regulatory authority should the security team identify as having primary jurisdiction over the data handling requirements?
Select an answer first - 19
A software company is developing a cloud-based application that will be used by both healthcare providers in the EU and financial institutions in the United States. The company is based in Canada. The security team must identify the regulatory authorities and standards that apply. Which of the following is the most comprehensive approach?
Select an answer first - 20
A software development team is starting a new project. The company has a policy that all code must be stored in an internal repository and all developers must use a specific IDE. What is the primary reason these company-wide policies must be incorporated into the software requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.