CSSLP Exam Questions & Answers
Certified Secure Software Lifecycle Professional • ISC2
100% money-back guarantee
Sample CSSLP Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You have a disaster scenario and you want to discuss it with your team members for getting appropriate responses of the disaster. In which of the following disaster recovery tests can this task be performed?
A simulation test is a method used to test the disaster recovery plans. It operates just like a structured walk-through test. In the simulation
test, the members of a disaster recovery team present with a disaster scenario and then, discuss on appropriate responses. These
suggested responses are measured and some of them are taken by the team. The range of the simulation test should be defined carefully for
avoiding excessive disruption of normal business activities.
Answer A is incorrect. The structured walk-through test is also known as the table-top exercise. In structured walk-through test, the
team members walkthrough the plan to identify and correct weaknesses and how they will respond to the emergency scenarios by stepping
in the course of the plan. It is the most effective and competent way to identify the areas of overlap in the plan before conducting more
challenging training exercises.
Answer B is incorrect. A full-interruption test includes the operations that shut down at the primary site and are shifted to the recovery
site according to the disaster recovery plan. It operates just like a parallel test. The full-interruption test is very expensive and difficult to
arrange. Sometimes, it causes a major disruption of operations if the test fails.
Answer C is incorrect. A parallel test includes the next level in the testing procedure, and relocates the employees to an alternate
recovery site and implements site activation procedures. These employees present with their disaster recovery responsibilities as they would
for an actual disaster. The disaster recovery sites have full responsibilities to conduct the day-to-day organization's business.
Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?
The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that
operates in a specified computing environment.
Answer C is incorrect. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and
create an agreement on the method for implementing the security requirements.
Answer A is incorrect. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation.
Answer B is incorrect. This phase ensures that it will maintain an acceptable level of residual risk.
Which of the following security controls works as the totality of protection mechanisms within a computer system, including hardware, firmware, and software, the combination of which is responsible for enforcing a security policy?
Trusted computing base (TCB) refers to hardware, software, controls, and processes that cause a computer system or network to be devoid
of malicious software or hardware. Maintaining the trusted computing base (TCB) is essential for security policy to be implemented
successfully.
Answer D is incorrect. Internet Protocol Security (IPSec) is a standard-based protocol that provides the highest level of VPN security.
IPSec can encrypt virtually everything above the networking layer. It is used for VPN connections that use the L2TP protocol. It secures both
data and password.
IPSec cannot be used with Point-to-Point Tunneling Protocol (PPTP).
Answer A is incorrect. The Common data security architecture (CDSA) is a set of layered security services and cryptographic framework.
It deals with the communications and data security problems in the emerging Internet and intranet application space. It presents an
infrastructure for building cross-platform, interoperable, security-enabled applications for client-server environments.
Answer B is incorrect. An application programming interface (API) is an interface implemented by a software program which enables it
to interact with other software. It facilitates interaction between different software programs similar to the way the user interface facilitates
interaction between humans and computers. An API is implemented by applications, libraries, and operating systems to determine their
vocabularies and calling conventions, and is used to access their services. It may include specifications for routines, data structures, object
classes, and protocols used to communicate between the consumer and the implementer of the API.
Which of the following secure coding principles and practices defines the appearance of code listing so that a code reviewer and maintainer who have not written that code can easily understand it?
Use a consistent coding style is one of the principles and practices that contribute to defensive coding. This principle defines the appearance
of code listing so that a code reviewer and maintainer who have not written that code can easily understand it. For this purpose, all
programmers of a team must follow the same guidelines.
Answer D is incorrect. Keep code simple and small defines that it is easy to verify the software security when a programmer uses small
and simple code base.
Answer A is incorrect. Make code forward and backward traceable defines that traceability is necessary in order to validate
requirements, prevent defects, and find and solve inconsistencies among all objects generated in the SDLC phases.
Answer B is incorrect. Review code during and after coding defines that code must be examined in order to identify coding errors in
modules.
Which of the following are Service Level Agreement (SLA) structures as defined by ITIL?
Each correct answer represents a complete solution. Choose all that apply.
ITIL defines 3 types of Service Level Agreement (SLA) structures, which are as follows:
1.Customer Based: It covers all services used by an individual customer group.
2.Service Based: It is one service for all customers.
3.Multi-Level: Some examples of Multi-Level SLA are 3 Tier SLA encompassing Corporate and Customer & Service Layers.
Answer C and A are incorrect. There are no such SLA structures as Segment Based and Component Based.
Get access to all 357 verified questions with detailed answers.
Unlock All CSSLP Questions