
Certified Secure Software Lifecycle Professional
Domain 4Objective 4
Perform Threat Modeling CSSLP Practice Questions (Page 5)
Part of the Secure Software Architecture and Design domain, which accounts for 15% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–18 in this domain), expect 2–3 from this objective — we provide 37 practice questions to prepare you well beyond it. (estimate)
37questions here
8free pages
11concepts
15%of the exam
Questions 21–25
- 21
Which of the following is a common method to reduce the attack surface of a system?
Select an answer first - 22
Which type of insider threat is characterized by an employee who unintentionally causes a security incident due to carelessness or lack of awareness?
Select an answer first - 23
A team is threat modeling a new REST API that allows clients to query customer records. The API uses API keys for authentication. The team is concerned about a threat where an attacker who obtains a valid API key could impersonate a legitimate client and access sensitive customer data. Which STRIDE category does this threat belong to?
Select an answer first - 24
A security team is triaging a list of vulnerabilities found in a recent scan. Vulnerability X has a CVSS v3.1 base score of 7.5, and Vulnerability Y has a base score of 6.5. Both vulnerabilities are in the same application and have the same exploitability. The team has time to fix only one vulnerability this sprint. Based on CVSS scores alone, which vulnerability should the team fix first?
Select an answer first - 25
A security analyst is investigating a series of anomalies in a corporate network. Over the past year, there have been multiple small data exfiltration events, each involving a different department. The attacker has used a variety of tools, including custom malware and legitimate system administration tools. The attacker has also maintained persistence by creating multiple backdoors. Which set of characteristics most strongly indicates an Advanced Persistent Threat (APT) rather than a series of unrelated attacks?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.