Practice CSSLP Secure Software Architecture And Design questions with full explanations on every answer.
Start practicing
Secure Software Architecture And Design — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are designing an input validation strategy. Which technique provides the best defense against Cross-Site Scripting (XSS)?
2An organization is moving a monolithic application to a microservices architecture. Which security design pattern is most effective for centralizing authentication while decoupling it from individual microservices?
3During a STRIDE threat modeling session for an API gateway, you identify a risk where an attacker could intercept data in transit. Which design pattern effectively mitigates this?
4When conducting a secure design review, which activity provides the most insight into potential session management vulnerabilities?
5During threat modeling, you are asked to classify data sensitivity. Which outcome is the primary goal of this activity?
6In a cloud-native environment, which design practice minimizes the impact of a compromised container?
7You are designing a web application and need to ensure the Principle of Least Privilege is applied to database access. Which approach best satisfies this requirement?
8Your team is adopting a 'Secure by Default' posture. Which design requirement should be included in the development specification?
9Which design principle is exemplified by implementing a Web Application Firewall (WAF) to inspect incoming traffic before it hits the application logic?
10In the context of secure design, what does 'Fail-safe defaults' mean when designing an authentication module?
11You are auditing a design that uses JSON Web Tokens (JWTs) for stateless authentication. Which vulnerability is most critical if the 'alg: none' attack is possible?
12When designing an application that requires secret management (e.g., API keys, database credentials), which design pattern is considered most secure?
13During a threat model, you identify a risk related to 'Broken Access Control'. Which design mitigation is best suited for this?
14A design uses a shared service account for multiple microservices to access a common database. Which architectural risk does this create?
15Which design principle suggests that developers should keep the security mechanisms simple to understand and implement?
16When designing an API, which approach best supports the 'Complete Mediation' principle?
17In a service-oriented architecture (SOA), which design pattern is most effective for ensuring that messages between services are not tampered with?
18Which design activity helps identify security requirements during the earliest phases of the SDLC?
19When evaluating a secure design, which TWO of the following practices are considered essential for secure session management?
20You are designing an application that integrates with a legacy system. Which design strategy minimizes the risk of the legacy system's vulnerabilities affecting your application?
21When designing a secure API, which THREE of the following practices are part of a 'defense in depth' strategy?
22When performing threat modeling using the STRIDE model, which TWO of the following threats are mitigated by implementing digital signatures?
23Which THREE of the following are key components of a 'Secure Design Review' process?
24Which TWO of the following strategies best implement the principle of 'Separation of Duties' in an application design?
25When designing for auditability, which THREE of the following pieces of information should be captured in security logs?
26Which TWO of the following design patterns improve the resilience of a secure system?
27When designing an application that relies on external APIs, which THREE of the following are necessary security considerations?
28Which TWO of the following design choices mitigate the risk of 'Broken Object-Level Authorization' (BOLA)?
The Secure Software Architecture And Design domain covers the key concepts tested in this area of the CSSLP exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CSSLP domains — no account required.
The Courseiva CSSLP question bank contains 28 questions in the Secure Software Architecture And Design domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Secure Software Architecture And Design domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included