
Certified Secure Software Lifecycle Professional
Domain 7Objective 10
Perform Vulnerability Management (e.g., Tracking, Triaging, Common Vulnerabilities and Exposures (CVE)) CSSLP Practice Questions (Page 5)
Part of the Secure Software Deployment, Operations, Maintenance domain, which accounts for 11% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–13 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
7concepts
11%of the exam
Questions 21–25
- 21
Which of the following is a related source that can supplement CVE data for assessing vulnerability relevance?
Select an answer first - 22
What should a vulnerability report to stakeholders include?
Select an answer first - 23
What does vulnerability lifecycle management encompass?
Select an answer first - 24
A security team is reviewing a CVE for a vulnerability in a widely used open-source library. The CVE description mentions that the vulnerability is only exploitable if the library is used in a specific configuration. The team's applications use the library in a different configuration. What should the team do?
Select an answer first - 25
A security analyst discovers a new vulnerability in a custom-built internal application. The analyst wants to determine if this vulnerability is already known and publicly documented. Which action should the analyst take to identify the vulnerability and assess its relevance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.