Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 4Objective 5

Perform Architectural Risk Assessment and Design Reviews CSSLP Practice Questions (Page 1)

Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts
15%of the exam

Questions 1–5

  1. 1foundation · easy

    What is the primary purpose of an architectural risk assessment in secure software design?

    Select an answer first
  2. 2expert · hard

    A company is designing a new online payment system that will handle credit card transactions. The architecture includes a web front end, a payment service, and a database. The team is performing an architectural risk assessment and is examining the data flow between the payment service and the database. They notice that the payment service uses a shared database account with full administrative privileges. What is the most significant architectural risk associated with this design?

    Select an answer first
  3. 3application · medium

    A software development team is about to start a major redesign of a legacy application. The security lead wants to conduct a security-focused design review before the implementation begins. What is the primary purpose of this design review?

    Select an answer first
  4. 4application · medium

    A manufacturing company is designing a new IoT platform that collects sensor data from factory equipment and sends it to a cloud-based analytics service. The architecture uses MQTT for communication between devices and the cloud. The risk assessment identifies that the MQTT broker does not require authentication, allowing any device to publish or subscribe to topics. Which mitigation strategy is most appropriate for this risk?

    Select an answer first
  5. 5expert · hard

    A security architect is conducting a threat model for a new healthcare application that integrates with a third-party lab results system. The architecture includes a web portal, an API, and a database. The team is using STRIDE and has identified a threat where an attacker could modify lab results in transit between the API and the third-party system. Which STRIDE category does this threat belong to, and what is the most appropriate mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.