Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 2Objective 3

Outline Strategy and Roadmap CSSLP Practice Questions (Page 5)

Part of the Secure Software Lifecycle Management domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
11%of the exam

Questions 21–25

  1. 21application · medium

    A software development organization is adopting a secure SDLC framework. They want to integrate security checkpoints into their existing agile development process. Which approach best aligns security checkpoints with the agile lifecycle?

    Select an answer first
  2. 22foundation · easy

    What is the primary responsibility of the security team in a security gate review?

    Select an answer first
  3. 23foundation · easy

    Why is it important for checkpoint criteria to be measurable and actionable?

    Select an answer first
  4. 24expert · hard · select all that apply

    A security checkpoint is scheduled for the end of the coding phase. The checkpoint criteria require that all critical and high-severity vulnerabilities are resolved. The team has fixed all critical vulnerabilities, but two high-severity vulnerabilities are still open. The project manager wants to proceed to testing. Which actions are appropriate? (Select all that apply.)

    Select an answer first
  5. 25foundation · easy

    What is the first step in responding to a failed control gate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.