Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 5Objective 3

Implement Security Controls (e.g., Watchdogs, File Integrity Monitoring, Anti-Malware) CSSLP Practice Questions (Page 3)

Part of the Secure Software Implementation domain, which accounts for 14% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~10–17 in this domain), expect 2–3 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)

20questions here
4free pages
4concepts
14%of the exam

Questions 11–15

  1. 11application · medium

    A government agency is deploying a new application on a hardened Linux server. The agency's security policy requires that any unauthorized change to the application's configuration files be detected and reported within 15 minutes. The team needs to implement a control that meets this requirement. What should the team implement?

    Select an answer first
  2. 12application · medium

    A company is deploying a new application on a server that is accessible from the internet. The application is critical to the business and must be available 24/7. The security team wants to ensure that the application does not hang, that its configuration files are not tampered with, and that it is protected from malware. The team has a limited budget and must choose the most effective controls. Which combination of controls should the team implement?

    Select an answer first
  3. 13expert · hard

    A security team is deploying a file integrity monitoring (FIM) solution for a critical application server. The team is concerned about the performance impact of running FIM on the server, as the application is I/O intensive. The team wants to minimize the performance impact while still detecting unauthorized changes to critical files. What should the team do?

    Select an answer first
  4. 14expert · hard

    A company is deploying a new application in a containerized environment. The security team is concerned about the risk of malware being introduced through a compromised container image. The team wants to implement a control that can detect and block malicious code before it is deployed. However, the team is also concerned about the performance impact of scanning every container image at runtime. What should the team do?

    Select an answer first
  5. 15application · medium

    A financial services company maintains a fleet of Linux servers running a custom trading application. The security team suspects that an attacker may have modified the application binary or its configuration files on one of the servers. The team wants to detect any unauthorized changes to these critical files as they happen, and also be able to verify the integrity of the files after a suspected compromise. What should the team implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.