Courseiva

CSSLP · domain

Secure Software Requirements

Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Requirements practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

26 questions8 easy9 medium9 hard

Focused practice

Practice Secure Software Requirements questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Secure Software Requirements

Secure Software Requirements questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Secure Software Requirements exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Secure Software Requirements questions (26)

Click any question to see the full explanation, or start a practice session above.

1

When designing a system that must satisfy both HIPAA and local privacy laws, which requirement approach is most appropriate?

Hard
2

You are leading a threat modeling session for a new cloud-native application. You identify a potential threat where an attacker attempts to inject malicious SQL queries into the search bar. Which technique should you employ to document this behavior during the Secure Software Requirements phase?

Medium
3

A stakeholder requests a feature that allows users to bypass password complexity requirements for 'internal testing accounts.' As a CSSLP, what is your first step in requirements analysis?

Medium
4

Which THREE items should be included in a 'Security Requirements Traceability Matrix'?

Medium
5

You are determining compliance requirements for a software product that handles PII. Which requirement is essential for demonstrating 'Privacy by Design'?

Hard
6

Which THREE categories are typically used to classify security requirements?

Easy
7

In the context of 'Secure Software Requirements', what should the security team do when they encounter a conflict between usability and security?

Medium
8

What is the primary goal of performing a 'Security Gap Analysis' during the requirements phase?

Easy
9

Which document is essential to map regulatory compliance requirements to specific software features?

Easy
10

Which TWO factors are critical when identifying compliance requirements for software that processes cross-border financial transactions?

Medium
11

Which phase of the secure software lifecycle is the most cost-effective for identifying and correcting security requirements?

Easy
12

Which THREE factors must be considered when defining 'Compliance Requirements' for an international software product?

Hard
13

When updating requirements for a legacy system to improve its security posture, which THREE actions should the CSSLP prioritize?

Hard
14

When gathering security requirements, what is the primary challenge when dealing with 'shadow IT' within a large enterprise?

Medium
15

During a project migration to GDPR compliance, the development team must ensure that personal data is deleted upon user request. Where should these specific data lifecycle constraints be documented to ensure they influence the architectural design?

Hard
16

An application requires multi-factor authentication (MFA) for administrative access. During requirements gathering, the security team determines that SMS-based MFA is insufficient for high-risk accounts. What documentation artifact should reflect this specific requirement?

Medium
17

You are reviewing the requirements for a legacy system integration. The system currently transmits credentials over plaintext protocols. What is the priority for the security requirements phase?

Hard
18

Which TWO inputs are most important when developing 'Abuse Cases'?

Easy
19

Which TWO methods are effective for eliciting security requirements from non-technical business stakeholders?

Hard
20

When gathering requirements for a new healthcare application, which regulation must be consulted to ensure the proper handling of Protected Health Information (PHI)?

Easy
21

You are managing requirements for a distributed microservices application. You need to ensure that service-to-service communication is encrypted. Which requirement type best categorizes this constraint?

Hard
22

You are eliciting security requirements for an application that must comply with PCI-DSS. What is the most effective way to identify the scope of the systems requiring the highest level of security?

Easy
23

You are analyzing an application to prevent unauthorized API access. Which requirement elicitation technique is best suited to identify potential entry points that an attacker might exploit?

Medium
24

Which TWO of the following are primary benefits of including security requirements early in the SDLC?

Medium
25

Which of the following describes the purpose of 'misuse case' modeling?

Easy
26

A government client requires that all software be validated against FIPS 140-3 standards. During requirements gathering, what is the most important step for the cryptographic module implementation?

Hard

Frequently asked questions

What does the Secure Software Requirements domain cover on the CSSLP exam?
Secure Software Requirements questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 26 Secure Software Requirements questions in the CSSLP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure Software Requirements questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Requirements Practice Questions