Official Bank 0/357

Certified Secure Software Lifecycle Professional (CSSLP) - ISC2 Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
357 Total Questions
1
Question
You work as a project manager for BlueWell Inc. You are working on a project and the management wants a rapid and cost-effective means for establishing priorities for planning risk responses in your project. Which risk management process can satisfy management's objective for your project?
Options
A Rolling wave planning
B Qualitative risk analysis
C Quantitative analysis
D Historical information
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
The Software Configuration Management (SCM) process defines the need to trace changes, and the ability to verify that the final delivered software has all of the planned enhancements that are supposed to be included in the release. What are the procedures that must be defined for each software project to ensure that a sound SCM process is implemented? Each correct answer represents a complete solution. Choose all that apply.
Select 5
Options
A Configuration identification
B Configuration status accounting
C Configuration audits
D Configuration implementation F.Configuration deployment
E Configuration change control
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
To help review or design security controls, they can be classified by several criteria. One of these criteria is based on time. According to this criteria, which of the following controls are intended to prevent an incident from occurring?
Options
A Detective controls
B Corrective controls
C Preventive controls
D Adaptive controls
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Samantha works as an Ethical Hacker for we-are-secure Inc. She wants to test the security of the we- are-secure server for DoS attacks. She sends large number of ICMP ECHO packets to the target computer. Which of the following DoS attacking techniques will she use to accomplish the task?
Options
A Ping flood attack
B Smurf dos attack
C Teardrop attack
D Land attack
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the following processes does the decomposition and definition sequence of the Vee model include? Each correct answer represents a part of the solution. Choose all that apply.
Select 4
Options
A Security requirements allocation
B Component integration and test
C High level software design
D System security analysis
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.