Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 7Objective 11

Incorporate Runtime Protection (e.g., Runtime Application Self Protection (RASP), Web Application Firewall (WAF), Address Space Layout Randomization (ASLR), Dynamic Execution Prevention) CSSLP Practice Questions (Page 1)

Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
11%of the exam

Questions 1–5

  1. 1application · medium

    A company's WAF has been in production for six months. The security team notices that the WAF is blocking legitimate user traffic after a recent application update introduced a new URL parameter format. The team needs to restore service quickly while maintaining protection. What should the team do first?

    Select an answer first
  2. 2application · medium

    An e-commerce platform uses a RASP agent in its Java application. After a routine update to the RASP rules, the security team observes that the agent is blocking a high volume of requests from a new, legitimate marketing campaign that uses URL shorteners. The team needs to maintain protection while allowing the campaign traffic. What should the team do?

    Select an answer first
  3. 3foundation · easy

    During which phase of the SDLC should runtime protection mechanisms be incorporated?

    Select an answer first
  4. 4foundation · easy

    How does ASLR mitigate the exploitation of memory corruption vulnerabilities?

    Select an answer first
  5. 5expert · hard

    A large online payment platform uses both a WAF and RASP. The WAF blocks common web attacks, while RASP monitors internal behavior. After a new feature release, the security team observes that RASP is generating a high number of false positives, blocking legitimate transactions. The WAF is not blocking these transactions. The team must restore service immediately but cannot disable RASP entirely due to compliance requirements. What should the team do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.