
Certified Secure Software Lifecycle Professional
Domain 4Objective 2
Perform Secure Interface Design CSSLP Practice Questions (Page 7)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
9concepts
15%of the exam
Questions 31–32
- 31
A team is designing a custom protocol for IoT devices to send sensor data to a central server. The protocol uses a simple sequence number to prevent replay attacks. However, an attacker has been able to capture and replay valid messages. What is the most likely weakness in the protocol design?
Select an answer first - 32
A security team is reviewing an API that allows users to update their profile information. The API accepts JSON payloads and stores data in a database. The team has identified that the API is vulnerable to SQL injection. Which mitigation is most effective and should be implemented first?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSSLP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.