
Certified Secure Software Lifecycle Professional
Domain 6Objective 4
Identify Undocumented Functionality CSSLP Practice Questions (Page 5)
Part of the Secure Software Testing domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)
24questions here
5free pages
5concepts
14%of the exam
Questions 21–24
- 21
Which of the following is a common source of undocumented functionality in software?
Select an answer first - 22
How can undocumented functionality lead to compliance violations?
Select an answer first - 23
A security team discovers an undocumented 'admin' account in a legacy application that is still in production. The account was created by a former employee and is not documented. The application is critical to business operations and cannot be taken offline for an extended period. What is the most appropriate immediate action?
Select an answer first - 24
A penetration tester is assessing a web application for undocumented functionality. The tester has no access to the source code but can interact with the application. Which technique would be most effective in discovering hidden endpoints or debug interfaces?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.