
Certified Secure Software Lifecycle Professional
Domain 7Objective 1
Perform Operational Risk Analysis CSSLP Practice Questions (Page 5)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
8concepts
11%of the exam
Questions 21–25
- 21
A company is integrating its customer-facing web application with a legacy on-premises system that contains sensitive customer data. The integration will be done via a new API. The security team is concerned about the risk of data exposure. The company has a strict requirement that customer data must not be cached or stored outside the on-premises environment. What is the most important control to implement?
Select an answer first - 22
What is a common operational risk when integrating a system with a third-party API?
Select an answer first - 23
A company is integrating its new inventory management system with a third-party logistics provider's API. The integration will transmit order and shipment data. The security team is performing a risk analysis. What is the most important risk to evaluate?
Select an answer first - 24
Which operational risk is most directly associated with configuration drift in a production environment?
Select an answer first - 25
Why is it important for end users to receive training on the proper handling of sensitive data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.