ISC2 · CSSLP

ISC2 CSSLP Exam Practice Questions

350 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 350 questions in this pack

Question 1

You work as a Network Auditor for Net Perfect Inc. The company has a Windows-based network. While auditing the company's network, you are facing problems in searching the faults and other entities that belong to it.

Which of the following risks may occur due to the existence of these problems?

  1. Residual risk
  2. Secondary risk
  3. Detection risk
  4. Inherent risk
Show answer and explanation

Correct answer: C. Detection risk

Detection risk refers to the risk that an auditor will fail to detect faults, errors, or other entities during an audit examination. When an auditor faces problems searching for faults and other network entities, this directly describes detection risk, the possibility that control deficiencies or anomalies will not be discovered through the audit process.

Why the other options are wrong

  • A. Residual risk is the risk remaining after controls have been implemented, not the risk of failing to find faults during an audit.
  • B. Secondary risk refers to risks created as a consequence of implementing a control, unrelated to audit detection failures.
  • D. Inherent risk is the risk that exists in the absence of controls, independent of the auditor's ability to search for problems.

Question 2

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information.

Which of the following participants are required in a NIACAP security assessment? Each correct answer represents a part of the solution.

Choose all that apply.

  1. Certification agent
  2. Designated Approving Authority
  3. IS program manager
  4. Information Assurance Manager
  5. User representative
Show answer and explanation

Correct answer: A, B, C, E

A. Certification agent B. Designated Approving Authority C. IS program manager E. User representative The NIACAP security assessment requires specific participants to conduct the certification and accreditation of systems handling national security information. The Certification Agent leads the technical assessment, the Designated Approving Authority is responsible for accreditation decisions, the IS Program Manager represents the organization's information systems, and the User Representative ensures user needs and concerns are addressed. The Information Assurance Manager is not required as a distinct participant role in the standard NIACAP process.

Why the other options are wrong

  • D. The Information Assurance Manager is not listed as a required participant in the standard NIACAP assessment process roles.

Question 3

Which of the following penetration testing techniques automatically tests every phone line in an exchange and tries to locate modems that are attached to the network?

  1. Demon dialing
  2. Sniffing
  3. Social engineering
  4. Dumpster diving
Show answer and explanation

Correct answer: A. Demon dialing

Demon dialing is an automated penetration testing technique that systematically tests every telephone line in an exchange to identify and locate modems attached to the network. This technique was historically used to discover unauthorized or hidden modems that could serve as entry points into a network.

Why the other options are wrong

  • B. Sniffing is a passive technique for capturing network traffic, not an automated method for testing phone lines.
  • C. Social engineering is a non-technical attack that manipulates people into divulging information, not an automated phone line testing method.
  • D. Dumpster diving is a physical security bypass technique involving searching through trash for sensitive information, unrelated to phone line testing.

See all 10 free questions Get the full pack, US$39

350 practice questions for ISC2 Certified Secure Software Lifecycle Professional (CSSLP), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong, across all eight CSSLP domains.

  • 350 questions across all eight CSSLP domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A CSSLP attempt costs US$599. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 350 questions

What makes the CSSLP hard

It is ISC2 thinking applied to software, so the technically correct answer often loses to the one that follows the process. Developers expect a secure coding quiz and find a lifecycle governance exam instead.

The eight domains follow the SDLC from start to finish: security requirements and misuse cases, threat modelling in design, secure coding and how it is verified, testing strategy, and the domain that catches most people out, supply chain, from third-party components to SBOMs. Throughout, expect the familiar ISC2 pattern of two defensible answers, where the preferred one manages risk earliest and most systematically.

The weighting is unusually even. No domain is under 10% or over 15%, so nothing can safely be skipped. Architecture and design is the largest at 15%, with implementation and testing at 14% each.

About the exam

CSSLP certifies building security into the whole software lifecycle: requirements, design, implementation, testing, deployment and supply chain. It requires 4 years of SDLC experience (or 3 with a relevant degree, and an Associate route is available). Valid for three years, with CPE credits and an annual maintenance fee.

Exam domains

  • Secure software concepts: 12%
  • Secure software lifecycle management: 11%
  • Secure software requirements: 13%
  • Secure software architecture and design: 15%
  • Secure software implementation: 14%
  • Secure software testing: 14%
  • Secure software deployment, operations and maintenance: 11%
  • Secure software supply chain: 10%

125 questions, 3 hours, multiple choice and advanced item types, pass mark 700 out of 1000, US$599 per attempt, at a Pearson VUE centre, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISC2 CSSLP pack?

350 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.