
Certified Secure Software Lifecycle Professional
Domain 7Objective 11
Incorporate Runtime Protection (e.g., Runtime Application Self Protection (RASP), Web Application Firewall (WAF), Address Space Layout Randomization (ASLR), Dynamic Execution Prevention) CSSLP Practice Questions (Page 6)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
6concepts
11%of the exam
Questions 26–29
- 26
What is the main goal of Data Execution Prevention (DEP)?
Select an answer first - 27
What is the primary function of a Web Application Firewall (WAF)?
Select an answer first - 28
A government agency deploys a public-facing web application and wants to protect it from OWASP Top 10 attacks. The agency has a strict requirement that all security controls must be managed by the agency's own staff, not the cloud provider. The application runs on a virtual machine in a cloud environment. What should the agency implement?
Select an answer first - 29
A software company is adopting a DevOps model and wants to integrate runtime protection into its CI/CD pipeline for a containerized web application. The security team wants to ensure that WAF rules are tested before they reach production and that updates are rolled back automatically if they cause errors. What should the team implement?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.