
Certified Secure Software Lifecycle Professional
Domain 4Objective 5
Perform Architectural Risk Assessment and Design Reviews CSSLP Practice Questions (Page 2)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
15%of the exam
Questions 6–10
- 6
A security team is analyzing risks for a new online payment system. They have identified a risk that a SQL injection vulnerability in the payment processing module could allow an attacker to access the entire customer database. They estimate the likelihood of exploitation as high and the impact as severe. What should the team do next?
Select an answer first - 7
A company is conducting an architectural risk assessment for a new e-commerce platform. The team has identified the following risks: (1) a potential SQL injection in the product search feature, (2) a lack of encryption for customer payment data at rest, and (3) a denial of service vulnerability in the API. The company has limited resources and can only mitigate two of the three risks in the current release. Which two risks should be prioritized for mitigation?
Select an answer first - 8
A company is conducting a design review for a new customer-facing application that will handle sensitive personal data. The review team is composed of the lead architect, a security engineer, and a project manager. The team is evaluating the architecture against security requirements. Which approach is most effective for the design review?
Select an answer first - 9
A development team is about to begin a design review for a new customer portal. The security lead wants to ensure that the review is effective. Which step is most important to include in the design review process?
Select an answer first - 10
A large enterprise is adopting a microservices architecture for a new customer-facing application. The security team is integrating architectural risk assessment and design reviews into the development process. The team is concerned about the risk of an attacker exploiting a vulnerability in one service to access data in another service. They want to implement a mitigation that is both effective and does not significantly impact performance. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.