Free CSSLP Practice Test Questions and Answers (2026) | Cert Empire Practice Questions
Free preview: 20 questions.
ISC2 CSSLP
Q: 1
Security is a state of well-being of information and infrastructures in which the possibilities of
successful yet undetected theft, tampering, and/or disruption of information and services are kept
low or tolerable. Which of the following are the elements of security? Each correct answer
represents a complete solution. Choose all that apply.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which of the following phases of NIST SP 800-37 C&A methodology examines the residual risk for
acceptability, and prepares the final security accreditation package?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
In which of the following testing methods is the test engineer equipped with the knowledge of
system and designs test cases or test data based on system knowledge?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
The Project Risk Management knowledge area focuses on which of the following processes?
Each correct answer represents a complete solution. Choose all that apply.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnerability
scenario using some functions. Which of the following are functions that are used by the dynamic
analysis tools and are summarized in the NIST SAMATE? Each correct answer represents a complete
solution. Choose all that apply.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Which of the following steps of the LeGrand Vulnerability-Oriented Risk Management method
determines the necessary compliance offered by risk management practices and assessment of risk
levels?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
DRAG DROP
Security code review identifies the unvalidated input calls made by an attacker and avoids those calls
to be processed by the server. It performs various review checks on the stained calls of servlet for
identifying unvalidated input from the attacker. Choose the appropriate review checks and drop
them in front of their respective functions.


Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Which of the following are examples of passive attacks?
Each correct answer represents a complete solution. Choose all that apply.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
An asset with a value of $600,000 is subject to a successful malicious attack threat twice a year. The
asset has an exposure of 30 percent to the threat. What will be the annualized loss expectancy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
Which of the following statements about a host-based intrusion prevention system (HIPS) are true?
Each correct answer represents a complete solution. Choose two.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
Which of the following statements describe the main purposes of a Regulatory policy?
Each correct answer represents a complete solution. Choose all that apply.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
You work as an analyst for Tech Perfect Inc. You want to prevent information flow that may cause a
conflict of interest in your organization representing competing clients. Which of the following
security models will you use?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
The DARPA paper defines various procedural patterns to perform secure system development
practices. Which of the following patterns does it include?
Each correct answer represents a complete solution. Choose three.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Software Development Life Cycle (SDLC) is a logical process used by programmers to develop
software. Which of the following SDLC phases meets the audit objectives defined below:
System and data are validated.
System meets all user requirements.
System meets all control requirements.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
Which of the following strategies is used to minimize the effects of a disruptive event on a company,
and is created to prevent interruptions to normal business activity?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
You are responsible for network and information security at a large hospital. It is a significant concern
that any change to any patient record can be easily traced back to the person who made that change.
What is this called?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
DRAG DROP
RCA (root cause analysis) is an iterative and reactive method that identifies the root cause of various
incidents, and the actions required to prevent these incidents from reoccurring. RCA is classified in
various categories. Choose appropriate categories and drop them in front of their respective
functions.


Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
In which of the following DIACAP phases is residual risk analyzed?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
FILL IN THE BLANK Fill in the blank with an appropriate phrase. models address specifications, requirements, design, verification and validation, and maintenance activities.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
Fill in the blank with an appropriate security type. applies the internal security policies of the software applications when they are deployed.
Your Answer
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20