
Certified Secure Software Lifecycle Professional
Domain 4Objective 5
Perform Architectural Risk Assessment and Design Reviews CSSLP Practice Questions (Page 4)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)
23questions here
5free pages
8concepts
15%of the exam
Questions 16–20
- 16
A retail company is designing a new e-commerce platform that will handle customer orders and payments. The architecture includes a web application, a payment processing service, and a legacy inventory system. The team is performing an architectural risk assessment and is examining the data flows between components. They notice that the payment processing service sends transaction data to the legacy inventory system over an unencrypted internal network. What is the most appropriate way to categorize this risk?
Select an answer first - 17
A financial services company is designing a new customer-facing web application that will process loan applications. The architecture uses a microservices approach with an API gateway, a set of internal services, and a shared relational database. During the architectural risk assessment, the team identifies that the API gateway authenticates users but does not enforce fine-grained authorization, allowing any authenticated user to invoke any internal service endpoint. What is the most appropriate next step in the risk assessment process?
Select an answer first - 18
A team is conducting a design review of a new online banking application. The architecture includes a web server, an application server, and a database. The reviewer notices that the application server directly accesses the database using a highly privileged account. Which security best practice is being violated?
Select an answer first - 19
A company is integrating architectural risk assessment and design review activities into its SDLC. The security team wants to ensure that security is considered throughout the design phase. Which approach best integrates these activities?
Select an answer first - 20
A team is threat modeling a new social media application. They are using the STRIDE methodology and are analyzing the threat of an attacker spoofing a user's identity to post unauthorized content. Which STRIDE category does this threat fall under?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.