
Certified Secure Software Lifecycle Professional
Domain 7Objective 11
Incorporate Runtime Protection (e.g., Runtime Application Self Protection (RASP), Web Application Firewall (WAF), Address Space Layout Randomization (ASLR), Dynamic Execution Prevention) CSSLP Practice Questions (Page 5)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
11%of the exam
Questions 21–25
- 21
A software vendor ships a Windows desktop application that processes sensitive local files. Penetration testing revealed a buffer overflow in a legacy C++ module that cannot be patched immediately. The security team wants to reduce the likelihood of successful exploitation while the patch is developed. Which runtime protection mechanism should the team verify is enabled on target systems?
Select an answer first - 22
What is an essential activity for maintaining the effectiveness of runtime protection controls?
Select an answer first - 23
A security engineer is reviewing the exploitability of a memory-corruption vulnerability in a Linux application. The application is compiled with ASLR enabled, but the engineer notes that the vulnerability can still be exploited reliably. Which additional runtime protection should the engineer recommend to make exploitation significantly harder?
Select an answer first - 24
What is a key consideration when integrating runtime protection into the deployment phase?
Select an answer first - 25
A healthcare organization is deploying a new patient-portal web application. The compliance team requires runtime protection against OWASP Top 10 attacks, but the application is developed by a third party and the source code is not available for modification. The deployment must include a control that can be tuned without vendor involvement. What should the organization incorporate into the deployment pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.