Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Secure Software Lifecycle Professional

Domain 8Objective 5

Support Contractual Requirements (e.g., Intellectual Property Ownership, Code Escrow, Liability, Warranty, End-User License Agreement (EULA), Service-Level Agreements (SLA)) CSSLP Practice Questions (Page 3)

Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
10%of the exam

Questions 11–15

  1. 11expert · hard

    A software vendor is negotiating a contract with a large financial institution. The institution demands that the vendor indemnify it against all third-party IP infringement claims arising from the software. The vendor's counsel is concerned about unlimited exposure, especially because the institution will integrate the software into a larger platform with third-party components. Which indemnification clause best balances the vendor's risk and the institution's need for protection?

    Select an answer first
  2. 12expert · hard

    A company is deploying a software product that includes a EULA with a 'shrink-wrap' or 'click-through' agreement. The company's procurement team wants to ensure the EULA is enforceable. Which factor is most important for the enforceability of the EULA?

    Select an answer first
  3. 13application · medium

    A company is negotiating an SLA with a SaaS provider. The company's compliance team requires that the provider's data centers be located within the country where the company operates. The provider's standard SLA does not specify data center locations. Which action should the company take?

    Select an answer first
  4. 14application · medium

    A software vendor is negotiating a contract with a customer. The customer wants the vendor to be liable for any data breach caused by a vulnerability in the vendor's software. The vendor wants to limit its liability. Which clause is the most effective way for the vendor to limit its exposure while still providing some protection to the customer?

    Select an answer first
  5. 15application · medium

    A company is deploying a commercial software product to 500 employees. The vendor's EULA states the license is granted for 'one user' and prohibits sharing login credentials. The company's IT manager wants to ensure compliance. Which action is the most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.