Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 7Objective 11

Incorporate Runtime Protection (e.g., Runtime Application Self Protection (RASP), Web Application Firewall (WAF), Address Space Layout Randomization (ASLR), Dynamic Execution Prevention) CSSLP Practice Questions (Page 3)

Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)

29questions here
6free pages
6concepts
11%of the exam

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of Address Space Layout Randomization (ASLR)?

    Select an answer first
  2. 12expert · hard

    A company is deploying a new web application and must choose a WAF deployment model. The application has unpredictable traffic spikes and the company wants to minimize latency for users. The security team has limited expertise in managing WAF infrastructure. Which WAF deployment model best meets these requirements?

    Select an answer first
  3. 13expert · hard

    A company is deploying a new web application and must choose between a WAF and RASP. The application handles sensitive data and is subject to a regulation that requires runtime protection against injection attacks. The company has a small security team with limited time for tuning. The application is developed in-house and the team has full access to the source code. Which approach best balances protection and operational effort?

    Select an answer first
  4. 14application · medium

    A retail company runs a public-facing web storefront on Azure App Service. The security team wants to protect the application from common web attacks such as cross-site scripting (XSS) and SQL injection without modifying application code. The solution must be managed by the cloud provider and require minimal operational overhead. What should the security team configure?

    Select an answer first
  5. 15application · medium

    A financial services firm deploys a custom Java web application that handles sensitive transactions. The security team wants to detect and block SQL injection and command injection attempts that bypass the WAF because they originate from authenticated users exploiting business-logic flaws. The application must continue running without requiring a network architecture change. What should the security team implement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.