Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 7Objective 7

Perform Information Security Continuous Monitoring CSSLP Practice Questions (Page 3)

Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 35 practice questions to prepare you well beyond it. (estimate)

35questions here
7free pages
9concepts
11%of the exam

Questions 11–15

  1. 11application · medium

    A healthcare organization's continuous monitoring program collects and stores detailed patient access logs in a SIEM for security analysis. A new privacy regulation requires that personal data be retained only for a specific period and that access to this data be logged. What is the most appropriate action for the organization to take?

    Select an answer first
  2. 12foundation · easy

    Which type of observable data is typically a structured record of a specific action or occurrence, such as a user login or a firewall rule match?

    Select an answer first
  3. 13application · medium

    A security operations center monitors a web application. The SIEM uses a rule that flags any request containing a known SQL injection pattern. An attacker obfuscates the payload using URL encoding, and the rule does not fire. Which enhancement would most directly improve detection of this variant?

    Select an answer first
  4. 14application · medium

    After a malware outbreak, the incident response team eradicates the threat from all affected systems and restores them from clean backups. Before closing the incident, what is the most important remaining step in the incident response process?

    Select an answer first
  5. 15expert · hard

    During an incident, the SIEM shows that an attacker has compromised a server and is using it to scan the internal network. The incident response team wants to contain the threat while preserving evidence and minimizing business disruption. The server hosts a critical application that cannot be taken offline. Which action best balances these constraints?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.