Courseiva

CSSLP · domain

Secure Software Testing

Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Testing practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

28 questions7 easy12 medium9 hard

Focused practice

Practice Secure Software Testing questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Secure Software Testing

Secure Software Testing questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Secure Software Testing exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Secure Software Testing questions (28)

Click any question to see the full explanation, or start a practice session above.

1

Which THREE factors should be considered when prioritizing findings from a DAST scan?

Hard
2

You are designing a fuzz testing strategy for a binary protocol parser. Which type of fuzzing is most effective for discovering memory corruption vulnerabilities in this component?

Easy
3

During IAST implementation in a CI/CD pipeline, the agent reports a high number of false positives regarding SQL injection. What is the most likely cause?

Hard
4

When setting up a penetration testing lab for a web application, which THREE network configurations are recommended?

Hard
5

A company is implementing a Secure SDLC. Which phase is the most appropriate to start defining security test cases?

Medium
6

A security auditor is using OWASP ZAP and wants to perform an authenticated scan. Which ZAP feature should they use to maintain the session across different scan requests?

Medium
7

When designing a test case for secure API authentication, which THREE elements should be included?

Hard
8

Which TWO of the following represent common output formats for security testing reports?

Easy
9

A developer wants to ensure that a web application is resistant to SQL injection. Which test case should be included in the automated test suite?

Medium
10

Which TWO of the following practices are recommended when performing fuzz testing on a web service?

Medium
11

A security engineer is analyzing a report from a SAST tool (e.g., Fortify). A finding is marked as 'Low Confidence'. What does this imply?

Medium
12

You are performing a fuzzing campaign on a REST API. The API uses JSON Web Tokens (JWT). What is the most effective way to include these tokens in the fuzzer input?

Hard
13

Which TWO of the following are primary benefits of integrating SAST into the early stages of the SDLC?

Medium
14

When designing a test case for a secure authentication bypass, which THREE areas should be covered?

Medium
15

A security engineer is configuring SonarQube for a Java project. Which configuration step ensures that the SAST scan accurately identifies injection vulnerabilities by analyzing data flow paths?

Medium
16

When configuring a DAST scanner to test for Cross-Site Request Forgery (CSRF), what must the scanner be able to do?

Medium
17

Which testing methodology provides the best visibility into the internal logic of an application while it is running?

Easy
18

A developer is using AFL (American Fuzzy Lop) for fuzzing a C++ application. What is the primary requirement for achieving high coverage?

Medium
19

During a manual penetration test, you discover an insecure direct object reference (IDOR). What is the most appropriate next step in the test case design for this finding?

Easy
20

Which of the following is the primary purpose of a DAST scan in a DevSecOps environment?

Easy
21

You are integrating Snyk into a CI pipeline. The scan is failing the build even when no new vulnerabilities are introduced. What is the cause?

Hard
22

When using Burp Suite Professional to perform DAST against a web application with a complex multi-step form, what is the most effective way to ensure the scanner completes the workflow?

Medium
23

Which TWO of the following are common challenges when implementing IAST?

Medium
24

You are auditing a SAST tool's findings for a Java application. The tool flags a potential XSS in a JSP file, but the output is encoded using a library. How should you classify this finding?

Hard
25

When configuring a custom scan in Nessus to identify vulnerabilities in a web-based management interface, which setting is essential for deep authenticated scanning?

Hard
26

When performing automated security testing, which of the following is considered a 'false positive'?

Easy
27

You are configuring Checkmarx for a .NET application. The scan results consistently miss vulnerabilities in a third-party DLL. What is the most likely reason?

Hard
28

When performing a penetration test on an API, which tool is best suited for identifying broken object level authorization (BOLA)?

Easy

Frequently asked questions

What does the Secure Software Testing domain cover on the CSSLP exam?
Secure Software Testing questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 28 Secure Software Testing questions in the CSSLP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Secure Software Testing questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Testing Practice Questions