Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 4Objective 5

Perform Architectural Risk Assessment and Design Reviews CSSLP Practice Questions (Page 5)

Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 23 practice questions to prepare you well beyond it. (estimate)

23questions here
5free pages
8concepts
15%of the exam

Questions 21–23

  1. 21application · medium

    A healthcare startup is designing a patient portal that allows patients to view their medical records and book appointments. The architecture includes a web front end, a REST API, and a database containing PHI. The team is conducting a threat modeling exercise using STRIDE. They are examining the data flow from the web front end to the REST API. Which STRIDE category is most directly applicable to the risk of an attacker intercepting the data in transit between the front end and the API?

    Select an answer first
  2. 22foundation · easy

    What is a key activity when performing a design review?

    Select an answer first
  3. 23foundation · easy

    How does integrating architectural risk assessment with design reviews improve security posture?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CSSLP

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.