
Certified Secure Software Lifecycle Professional
Domain 4Objective 4
Perform Threat Modeling CSSLP Practice Questions (Page 2)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
11concepts
15%of the exam
Questions 6–10
- 6
A security architect is using PASTA to threat model a new online banking application. During the attack simulation stage, the architect wants to model the most likely attack path an adversary would take to compromise a user's account. The architect has identified several potential entry points, including the login page, the password reset flow, and the mobile app API. Which approach best aligns with PASTA's principles for this stage?
Select an answer first - 7
A security analyst has identified two vulnerabilities in a web application. Vulnerability A has a CVSS v3.1 base score of 9.8, and Vulnerability B has a base score of 4.2. The analyst has limited remediation resources and must prioritize which vulnerability to fix first. According to the CVSS scoring system, what should the analyst do?
Select an answer first - 8
During a threat modeling session, the team identifies a threat where an attacker could modify data in transit between the client and server. Which STRIDE category does this threat belong to?
Select an answer first - 9
Which of the following is an example of a credible source for threat intelligence?
Select an answer first - 10
What is the primary purpose of threat intelligence in the context of threat modeling?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.