Courseiva
Back to (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) questions

Scenario-based practice

Hard Difficulty Questions

Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CSSLP
exam code
(ISC)²
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CSSLP topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A security team implements a 'Separation of Duties' policy in the CI/CD pipeline. Which implementation is correct?

Question 2hardmultiple choice
Full question →

In an OAuth 2.0 flow, you are using the 'Authorization Code' grant type. You notice an attacker is attempting to intercept the code. Which security concept is being utilized by requiring the client_secret during the token exchange?

Question 3hardmultiple choice
Full question →

You are using the 'Complete Mediation' principle in your system's access control design. What does this require?

Question 4hardmultiple choice
Full question →

Which design activity helps identify security requirements during the earliest phases of the SDLC?

Question 5hardmulti select
Full question →

When performing threat modeling using the STRIDE model, which TWO of the following threats are mitigated by implementing digital signatures?

Question 6hardmulti select
Full question →

When designing for auditability, which THREE of the following pieces of information should be captured in security logs?

Question 7hardmultiple choice
Full question →

An organization is moving a monolithic application to a microservices architecture. Which security design pattern is most effective for centralizing authentication while decoupling it from individual microservices?

Question 8hardmultiple choice
Full question →

You are applying the Bell-LaPadula model to a secure software system. A user with 'Secret' clearance attempts to write data to a 'Top Secret' file. Based on the *-property, what is the outcome?

Question 9hardmultiple choice
Full question →

You are auditing a design that uses JSON Web Tokens (JWTs) for stateless authentication. Which vulnerability is most critical if the 'alg: none' attack is possible?

Question 10hardmultiple choice
Full question →

In a cloud-native environment, which design practice minimizes the impact of a compromised container?

Question 11hardmulti select
Full question →

When implementing a 'Zero Trust' architecture in software design, which THREE principles are fundamental?

Question 12hardmultiple choice
Full question →

When designing an application that requires secret management (e.g., API keys, database credentials), which design pattern is considered most secure?

Question 13hardmulti select
Full question →

In a DevSecOps pipeline, which TWO of the following are critical for ensuring the integrity of the software supply chain?

Question 14hardmultiple choice
Full question →

A design uses a shared service account for multiple microservices to access a common database. Which architectural risk does this create?

Question 15hardmultiple choice
Full question →

An application utilizes the Clark-Wilson integrity model. Which mechanism does it use to ensure that subjects only perform authorized operations on objects?

Question 16hardmultiple choice
Full question →

You are designing an application that integrates with a legacy system. Which design strategy minimizes the risk of the legacy system's vulnerabilities affecting your application?

Question 17hardmulti select
Full question →

Which TWO of the following design choices mitigate the risk of 'Broken Object-Level Authorization' (BOLA)?

Question 18hardmulti select
Full question →

In threat modeling, which THREE categories are explicitly defined by the STRIDE methodology?

Question 19hardmultiple choice
Full question →

When implementing file uploads, which practice is most effective in preventing remote code execution (RCE)?

Question 20hardmulti select
Full question →

When designing a secure API, which THREE of the following practices align with the principle of 'Defense-in-Depth'?

These CSSLP practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style CSSLP questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.