
Certified Secure Software Lifecycle Professional
Domain 2Objective 1
Manage Security Within a Software Development Methodology (e.g., Agile, Waterfall) CSSLP Practice Questions (Page 5)
Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
11%of the exam
Questions 21–25
- 21
In a Scrum team, a developer discovers a security flaw in a third-party library during a sprint. According to Agile principles, what should the developer do?
Select an answer first - 22
In a waterfall project, who is typically responsible for approving the security design before development begins?
Select an answer first - 23
An Agile team has a large amount of security debt, including several critical vulnerabilities. The team is under pressure to deliver new features. The security professional proposes a 'security sprint' to address the debt. What is a potential drawback of this approach?
Select an answer first - 24
In an Agile project, how are regulatory compliance requirements typically addressed?
Select an answer first - 25
An Agile team is planning the next sprint. The product owner wants to prioritize new features, but the security professional has identified critical security debt that must be addressed. What is the best way to handle this conflict?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.