
Certified Secure Software Lifecycle Professional
Domain 4Objective 6
Model (non-Functional) Security Properties and Constraints CSSLP Practice Questions (Page 4)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
5concepts
15%of the exam
Questions 16–20
- 16
A company is developing a new employee self-service portal. The portal must allow employees to view their own payroll information, but not that of other employees. Which non-functional security property is most directly required?
Select an answer first - 17
A software architect has defined a security constraint that all external input must be validated before processing. The development team is implementing the module that handles file uploads. Which validation approach best ensures the constraint is enforced consistently across all entry points?
Select an answer first - 18
Which validation technique uses mathematical proofs to verify that a system design satisfies specified security properties?
Select an answer first - 19
What is the primary purpose of a security constraint in software architecture?
Select an answer first - 20
A security architect has specified a constraint that all passwords must be stored using a strong hashing algorithm. The development team has implemented password storage. Which validation activity is most appropriate to verify the constraint?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.