
Certified Secure Software Lifecycle Professional
Domain 7Objective 9
Perform Patch Management (e.g. Secure Release, Testing) CSSLP Practice Questions (Page 2)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 19 practice questions to prepare you well beyond it. (estimate)
19questions here
4free pages
5concepts
11%of the exam
Questions 6–10
- 6
A security audit reveals that several servers are missing a critical security patch. The patch was deployed to most servers, but a few were missed due to being offline at the time of deployment. What is the most appropriate action to take to ensure compliance?
Select an answer first - 7
An organization's IT team is preparing to deploy a new security patch to its customer-facing web application. The patch modifies the authentication module. The team has a staging environment that mirrors production. What is the most critical testing step to perform before deploying the patch to production?
Select an answer first - 8
A company's patch management process is being reviewed. The process currently consists of: identifying available patches, deploying them to production, and then verifying they are installed. A security consultant points out that the process is missing a critical phase. Which phase is most likely missing?
Select an answer first - 9
Which activity is essential for auditing patch deployment after a patch has been released?
Select an answer first - 10
In the patch management lifecycle, which phase immediately follows the identification of a new security patch and precedes its deployment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.