
Certified Secure Software Lifecycle Professional
Domain 1Objective 2
Understand Security Design Principles CSSLP Practice Questions (Page 5)
Part of the Secure Software Concepts domain, which accounts for 12% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~8–14 in this domain), expect 4–7 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
10concepts
12%of the exam
Questions 21–25
- 21
Which implementation of segregation of duties involves splitting a secret into multiple parts, each held by a different person?
Select an answer first - 22
Which principle is an example of open design in practice?
Select an answer first - 23
Which security principle states that the security of a system should not depend on the secrecy of its design?
Select an answer first - 24
A critical infrastructure system uses a redundant pair of servers in an active-passive configuration. The passive server is identical to the active server and is located in the same data center. The security team is concerned about a single point of failure. Which improvement best addresses this concern?
Select an answer first - 25
A web application caches user credentials in a client-side cookie to avoid re-authentication on every request. A security review flags this as a violation of complete mediation. What is the most appropriate remediation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.