ISC2 CSSLP Certification Sample Questions

CSSLP Dumps, CSSLP Dumps, CSSLP PDF, CSSLP VCE, ISC2 CSSLP VCE, ISC2 CSSLP PDFThe purpose of this Sample Question Set is to provide you with information about the ISC2 Secure Software Lifecycle Professional exam. These sample questions will make you very familiar with both the type and the difficulty level of the questions on the CSSLP certification test. To get familiar with real exam environment, we suggest you try our Sample ISC2 CSSLP Certification Practice Exam. This sample practice exam gives you the feeling of reality and is a clue to the questions asked in the actual ISC2 Certified Secure Software Lifecycle Professional (CSSLP) certification exam.

These sample questions are simple and basic questions that represent likeness to the real ISC2 CSSLP exam questions. To assess your readiness and performance with real time scenario based questions, we suggest you prepare with our Premium ISC2 CSSLP Certification Practice Exam. When you solve real time scenario based questions practically, you come across many difficulties that give you an opportunity to improve.

ISC2 CSSLP Sample Questions:

01. Software maintenance and support begins once the product has been delivered. Which of the following is not a recognized category of application maintenance activity?
a) Prevention
b) Correction
c) Adaptation
d) Diversification
 
02. Which of the following is the most important task when performing a design security review?
a) Decompose your application and be able to identify key items.
b) Attach performance metrics to the review process.
c) Use standardized graphics to document the data flow.
d) Highlight all security controls used in the system.
 
03. Secure configuration management is most useful for which of the following?
a) Sprint planning
b) Reviewing documentation
c) Securing data repositories
d) Preventing integrity breaches
 
04. Which of the following statements about an authorization to operate (ATO) is not true?
a) ATOs are not granted for an indefinite period of time.
b) An ATO may be denied, which basically means that the product may not be used within the organization's environment.
c) The software QA team is the entity that has the responsibility to issue an ATO.
d) ATO is primarily used in the federal government when security or operational integrity is a concern.
 
05. The fundamental benefit of a sandboxed environment is:
a) isolation and containment to reduce risk.
b) restricting access to code repositories.
c) identification of vulnerabilities in code with no false positives.
d) authentication and authorization.
 
06. Which of the following is the primary input to the development of abuse cases?
a) Risk results
b) Use cases
c) Complaints
d) Case reports
 
07. Which of the following can be used to provide non-repudiation?
a) Hashing
b) Symmetric encryption algorithms
c) Data loss prevention (DLP)
d) Digital signatures
 
08. Which type of control is intended to limit the extent of the damage caused by an incident?
a) Corrective controls
b) Compensating controls
c) Preventive controls
d) Detective controls
 
09. A security testing method also known as structure-based testing involves the direct analysis of source code, and requires the tester to know how the software is implemented and how it works. Which term does this describe?
a) Stress testing
b) White-box testing
c) Black-box testing
d) Unit testing
 
10. Which of the following cannot be directly affected by security monitoring?
a) Detecting violations of security policies and standards
b) Detecting intrusion attempts early on
c) Cryptography policy update
d) Forensics analysis

Answers:

Question: 01
Answer: d
Question: 02
Answer: a
Question: 03
Answer: d
Question: 04
Answer: c
Question: 05
Answer: a
Question: 06
Answer: b
Question: 07
Answer: d
Question: 08
Answer: a
Question: 09
Answer: b
Question: 10
Answer: c

Note: For any error in ISC2 Certified Secure Software Lifecycle Professional (CSSLP) certification exam sample questions, please update us by writing an email on feedback@edusum.com.

Rating: 4.7 / 5 (139 votes)