Courseiva
Back to (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CSSLP
exam code
(ISC)²
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CSSLP topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which TWO of the following are essential components for achieving 'Non-repudiation'?

Question 2easymulti select
Full question →

Which TWO of the following strategies best implement the principle of 'Separation of Duties' in an application design?

Question 3easymulti select
Full question →

When evaluating a secure design, which TWO of the following practices are considered essential for secure session management?

Question 4hardmulti select
Full question →

When performing threat modeling using the STRIDE model, which TWO of the following threats are mitigated by implementing digital signatures?

Question 5hardmulti select
Full question →

When designing for auditability, which THREE of the following pieces of information should be captured in security logs?

Question 6mediummulti select
Full question →

When designing an application that relies on external APIs, which THREE of the following are necessary security considerations?

Question 7easymulti select
Full question →

Which THREE of the following are key components of a 'Secure Design Review' process?

Question 8mediummulti select
Full question →

Which TWO of the following are recognized components of the 'Confidentiality, Integrity, and Availability' (CIA) triad?

Question 9hardmulti select
Full question →

When implementing a 'Zero Trust' architecture in software design, which THREE principles are fundamental?

Question 10hardmulti select
Full question →

In a DevSecOps pipeline, which TWO of the following are critical for ensuring the integrity of the software supply chain?

Question 11mediummulti select
Full question →

When designing a secure API, which THREE of the following practices are part of a 'defense in depth' strategy?

Question 12mediummulti select
Full question →

Which TWO of the following design patterns improve the resilience of a secure system?

Question 13hardmulti select
Full question →

Which TWO of the following design choices mitigate the risk of 'Broken Object-Level Authorization' (BOLA)?

Question 14easymulti select
Full question →

Which TWO of the following actions support the 'Open Design' security principle?

Question 15hardmulti select
Full question →

In threat modeling, which THREE categories are explicitly defined by the STRIDE methodology?

Question 16mediummulti select
Full question →

Which TWO of the following are examples of how software can maintain 'Integrity'?

Question 17hardmulti select
Full question →

When designing a secure API, which THREE of the following practices align with the principle of 'Defense-in-Depth'?

Question 18hardmulti select
Full question →

Which THREE of the following are recognized techniques for minimizing the attack surface of an API?

Question 19hardmulti select
Full question →

Which TWO methods are effective in hardening the production environment against 'Zero-Day' vulnerabilities?

Question 20hardmulti select
Full question →

Which TWO of the following are required to successfully implement a secure logging mechanism?

These CSSLP practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style CSSLP questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.