
Certified Secure Software Lifecycle Professional
Domain 7Objective 10
Perform Vulnerability Management (e.g., Tracking, Triaging, Common Vulnerabilities and Exposures (CVE)) CSSLP Practice Questions (Page 1)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
11%of the exam
Questions 1–5
- 1
A vulnerability management team has been tracking a vulnerability for several months. The vulnerability was remediated in the production environment, but the team has not yet closed the record. What is the most likely reason the record should remain open?
Select an answer first - 2
What is the primary goal of vulnerability triage?
Select an answer first - 3
What is the primary purpose of a vulnerability tracking system in secure software deployment?
Select an answer first - 4
What is the purpose of a CVE identifier?
Select an answer first - 5
A security analyst discovers a vulnerability in a third-party library used by multiple internal applications. The analyst needs to track the vulnerability across all affected applications. What is the most effective approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.