CSSLP · domain
Secure Software Architecture And Design
Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Architecture And Design practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Secure Software Architecture And Design questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Secure Software Architecture And Design
Secure Software Architecture And Design questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Secure Software Architecture And Design exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Secure Software Architecture And Design questions (28)
Click any question to see the full explanation, or start a practice session above.
During a threat model, you identify a risk related to 'Broken Access Control'. Which design mitigation is best suited for this?
Easy2In a cloud-native environment, which design practice minimizes the impact of a compromised container?
Hard3Which design principle is exemplified by implementing a Web Application Firewall (WAF) to inspect incoming traffic before it hits the application logic?
Easy4During a STRIDE threat modeling session for an API gateway, you identify a risk where an attacker could intercept data in transit. Which design pattern effectively mitigates this?
Medium5When designing an application that requires secret management (e.g., API keys, database credentials), which design pattern is considered most secure?
Hard6You are designing a web application and need to ensure the Principle of Least Privilege is applied to database access. Which approach best satisfies this requirement?
Easy7Your team is adopting a 'Secure by Default' posture. Which design requirement should be included in the development specification?
Medium8In a service-oriented architecture (SOA), which design pattern is most effective for ensuring that messages between services are not tampered with?
Medium9Which TWO of the following design choices mitigate the risk of 'Broken Object-Level Authorization' (BOLA)?
Hard10Which design activity helps identify security requirements during the earliest phases of the SDLC?
Hard11Which TWO of the following strategies best implement the principle of 'Separation of Duties' in an application design?
Easy12Which THREE of the following are key components of a 'Secure Design Review' process?
Easy13A design uses a shared service account for multiple microservices to access a common database. Which architectural risk does this create?
Hard14Which TWO of the following design patterns improve the resilience of a secure system?
Medium15Which design principle suggests that developers should keep the security mechanisms simple to understand and implement?
Easy16In the context of secure design, what does 'Fail-safe defaults' mean when designing an authentication module?
Medium17You are designing an application that integrates with a legacy system. Which design strategy minimizes the risk of the legacy system's vulnerabilities affecting your application?
Hard18When designing an application that relies on external APIs, which THREE of the following are necessary security considerations?
Medium19You are designing an input validation strategy. Which technique provides the best defense against Cross-Site Scripting (XSS)?
Medium20During threat modeling, you are asked to classify data sensitivity. Which outcome is the primary goal of this activity?
Easy21You are auditing a design that uses JSON Web Tokens (JWTs) for stateless authentication. Which vulnerability is most critical if the 'alg: none' attack is possible?
Hard22When conducting a secure design review, which activity provides the most insight into potential session management vulnerabilities?
Easy23When performing threat modeling using the STRIDE model, which TWO of the following threats are mitigated by implementing digital signatures?
Hard24An organization is moving a monolithic application to a microservices architecture. Which security design pattern is most effective for centralizing authentication while decoupling it from individual microservices?
Hard25When designing for auditability, which THREE of the following pieces of information should be captured in security logs?
Hard26When designing an API, which approach best supports the 'Complete Mediation' principle?
Easy27When evaluating a secure design, which TWO of the following practices are considered essential for secure session management?
Easy28When designing a secure API, which THREE of the following practices are part of a 'defense in depth' strategy?
MediumOther domains
All CSSLP exam domains
Frequently asked questions
- What does the Secure Software Architecture And Design domain cover on the CSSLP exam?
- Secure Software Architecture And Design questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 28 Secure Software Architecture And Design questions in the CSSLP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Software Architecture And Design questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.