Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 6Objective 4

Identify Undocumented Functionality CSSLP Practice Questions (Page 4)

Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
14%of the exam

Questions 16–20

  1. 16application · medium

    A healthcare organization is deploying a new patient portal. During testing, they discover an undocumented feature that allows users to view other patients' medical records by manipulating a URL parameter. The organization is subject to HIPAA regulations. What is the most critical risk associated with this undocumented functionality?

    Select an answer first
  2. 17application · medium

    A security analyst is reviewing a mobile application and finds that pressing the volume button five times quickly triggers a hidden debug menu that displays sensitive user data. The menu is not accessible through the normal user interface. What is this an example of?

    Select an answer first
  3. 18application · medium

    During a code review, a developer notices that a legacy module contains a commented-out block of code that, when uncommented, allows a user to bypass authentication by setting a specific cookie value. The comment says 'TODO: remove before release'. What is the most likely origin of this undocumented functionality?

    Select an answer first
  4. 19expert · hard

    A security analyst discovers an undocumented feature in a web application that allows users to escalate their privileges to administrator by sending a specific HTTP request. The feature is not documented and was likely left over from development. The application is used by a government agency and is subject to strict security requirements. What is the most significant risk posed by this undocumented functionality?

    Select an answer first
  5. 20foundation · easy

    Which of the following is a common example of undocumented functionality that could be left in a production application?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.