Courseiva

CISSP · domain

Software Development Security

Software Development Security covers how security is built into the software lifecycle rather than bolted on afterward. For CISSP, questions target secure coding practices, threat modeling, code review, and testing methods such as SAST, DAST, and penetration testing, plus how vulnerabilities like XSS, SQL injection, and broken access control are mitigated in web applications and APIs.

42 questions10 easy20 medium12 hard

Focused practice

Practice Software Development Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Software Development Security

Be able to select the right control for a given flaw: output encoding for XSS, parameterized queries for SQL injection, authorization checks for IDOR, and generic error messages to prevent information disclosure. The single most important thing is matching the mitigation to the vulnerability class and its root cause.

Secure coding practices: input validation, output encoding, parameterized queries, and centralized error handling

Security testing types: SAST on source code, DAST on running apps, IAST, and penetration testing

Threat modeling methodologies such as STRIDE and how they map to design-level mitigations

Software development lifecycle models, DevSecOps, and change management controls for code integrity

Watch out for

Common Software Development Security exam traps

  • ▸Confusing SAST with DAST: SAST analyzes source or bytecode without executing it, while DAST tests a running application from the outside.
  • ▸Treating input validation as sufficient for XSS; output encoding and context-aware escaping are the primary defenses.
  • ▸Assuming authentication alone prevents access control flaws; missing authorization checks on object references cause IDOR.

Question index

All Software Development Security questions (42)

Click any question to see the full explanation, or start a practice session above.

1

Which type of testing analyzes source code for security vulnerabilities without executing the program?

Medium
2

A security engineer is evaluating a new third-party software component for use in a critical application. Which document is most important to review to understand the component's supply chain security?

Hard
3

A development team is using a third-party library that is known to have a critical vulnerability. The team decides to continue using the library because it is widely used and the vulnerability has not been exploited. Which security risk is the team ignoring?

Hard
4

A security analyst is reviewing the error handling of an application. The application currently displays detailed stack traces to users when an exception occurs. Which of the following is the best practice for error handling in production?

Medium
5

During the requirements gathering phase of a software development project, which threat modeling methodology is most commonly used to identify threats such as spoofing, tampering, and elevation of privilege?

Easy
6

A security engineer is evaluating a web application for common vulnerabilities. The application uses a Content Management System (CMS) that is outdated and has known vulnerabilities. Additionally, the application displays detailed error messages and uses default administrative credentials. Which TWO of the following OWASP Top 10 categories are most relevant to these issues?

Medium
7

A security architect is designing an authentication system. To prevent session fixation attacks, which secure design principle should be implemented?

Hard
8

A developer is implementing cryptographic storage for sensitive user data. Which of the following is a cryptographic best practice?

Hard
9

During a security review of a web application, testers discover that the application discloses detailed error messages to users, including stack traces. Which secure coding best practice is being violated?

Medium
10

During a security assessment, a penetration tester discovers that a web application exposes internal IP addresses in error messages. Which vulnerability category does this represent?

Medium
11

A security analyst is reviewing a web application and notices that it includes a feature that allows users to view their own profile by providing a user ID in the URL (e.g., /profile?userid=123). The application does not verify that the logged-in user owns that profile. Which vulnerability is present?

Medium
12

A security team is reviewing a web application that allows users to search for products. The application uses a SQL database and constructs queries by concatenating user input directly into the SQL statement. Which of the following is the most effective mitigation against SQL injection attacks?

Medium
13

Which of the following is a secure coding practice to prevent SQL injection attacks?

Easy
14

A company is evaluating a third-party software library for use in their application. Which document provides a detailed inventory of the library's components and dependencies to help assess supply chain risk?

Hard
15

Which type of security testing involves analyzing source code for vulnerabilities without executing the code?

Easy
16

During a penetration test, a security analyst discovers that a web application allows an attacker to bypass authorization and view another user's private messages by simply changing a numeric ID in the URL. Which vulnerability is being exploited?

Hard
17

Which of the following is the primary purpose of output encoding in web application security?

Easy
18

A security engineer is hardening a web server before deploying a new application. Which TWO of the following are examples of security misconfiguration vulnerabilities that should be addressed?

Medium
19

A security team is performing a risk assessment on a legacy application that uses insecure deserialization. Which TWO of the following are recommended approaches to mitigate the risk of insecure deserialization?

Hard
20

A development team is designing a new application and wants to ensure that if a failure occurs, the system remains secure by default. Which design principle should they apply?

Medium
21

A security architect is reviewing a design for an e-commerce application. The architect recommends implementing defense in depth. Which of the following is an example of this principle?

Medium
22

A software development team is preparing to release a new application. The security manager requires that the application be tested for security vulnerabilities before deployment. Which of the following testing approaches is specifically designed to simulate real-world attacks against a running application?

Easy
23

A development team is implementing a web application that allows users to search for products. To prevent SQL injection attacks, which secure coding practice should be applied?

Medium
24

A development team is implementing cryptographic functions for a new application. They need to store passwords securely. Which of the following is the most appropriate approach?

Hard
25

A security architect is reviewing a web application's design and identifies several potential vulnerabilities. Which TWO of the following are effective mitigations for cross-site scripting (XSS) attacks?

Medium
26

A development team is fixing a stored cross-site scripting (XSS) vulnerability in a web application that displays user comments. The application stores comments in a database and renders them in HTML. Which of the following is the most secure approach to prevent XSS?

Hard
27

What is the primary purpose of a Web Application Firewall (WAF) in a deployment environment?

Easy
28

During a threat modeling session for a new online banking application, the team uses the STRIDE methodology. Which threat category addresses the risk of an attacker modifying transaction data in transit?

Medium
29

During a vulnerability assessment, a security analyst discovers that a web application uses a library known to be vulnerable to Log4Shell (CVE-2021-44228). Which type of vulnerability does this represent?

Hard
30

Which of the following is an example of an Insecure Direct Object Reference (IDOR) vulnerability?

Easy
31

During the requirements gathering phase of a secure SDLC, the team uses a threat modeling approach that focuses on identifying threats such as spoofing, tampering, and denial of service. Which threat modeling methodology is being employed?

Medium
32

A security architect is designing a system that must continue to function even when a component fails. The architect implements multiple layers of security controls so that if one fails, others still provide protection. Which principle is being applied?

Easy
33

During a code review, a developer identifies that the application uses a custom encryption algorithm for storing sensitive data. Which THREE of the following are secure cryptographic practices that should be recommended instead?

Medium
34

A security analyst is reviewing the authentication mechanism of a web application. Which TWO of the following are examples of broken authentication vulnerabilities?

Easy
35

A security analyst is reviewing a web application that handles financial transactions. Which TWO of the following are effective controls against Cross-Site Request Forgery (CSRF)?

Medium
36

A software development team is adopting secure coding practices. They decide to implement input validation for all user-supplied data. Which approach is recommended as the most effective for preventing injection attacks?

Easy
37

An organization is planning to acquire a new SaaS application for customer relationship management. Which THREE of the following should be included in the vendor security assessment?

Medium
38

A web application exposes an API that allows users to fetch data from internal network resources based on a URL parameter. An attacker discovers they can use this API to access internal servers that are not meant to be public. Which vulnerability is being exploited?

Medium
39

During a security audit of a web application, the following issues are found: (1) Session tokens are included in URLs, (2) The application does not invalidate session tokens after logout, and (3) Session tokens are predictable. Which THREE of the following controls are most appropriate to address these issues?

Medium
40

A security team is planning to integrate security testing into the software development lifecycle. They want to identify vulnerabilities early and often. Which TWO of the following testing methods should be implemented during the development phase (before deployment) to catch code-level vulnerabilities?

Hard
41

A security team is conducting a penetration test on a web application. They identify that the application is vulnerable to reflected cross-site scripting (XSS). Which of the following is the most effective mitigation?

Medium
42

A security architect is defining security requirements for a new software development project that will use an Agile methodology. The organization wants to ensure that security is integrated throughout the development lifecycle. Which TWO of the following practices BEST support this goal? (Choose two.)

Hard

Frequently asked questions

What does the Software Development Security domain cover on the CISSP exam?
Be able to select the right control for a given flaw: output encoding for XSS, parameterized queries for SQL injection, authorization checks for IDOR, and generic error messages to prevent information disclosure. The single most important thing is matching the mitigation to the vulnerability class and its root cause.
How many questions are in this domain?
This page lists all 42 Software Development Security questions in the CISSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Software Development Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cissp ISC2-CISSP cissp software security Practice Questions