ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A code review identifies a SQL injection flaw in a legacy payroll portal. Re-engineering the affected module would delay the release schedule, so the team immediately deploys a web application firewall rule that filters injection patterns and restricts access to the portal until it can be rewritten in the next development cycle. Which risk-treatment strategy are they applying?
Remediate the risk by permanently fixing the vulnerable code now
Transfer the risk to a third party through cyber-insurance
Accept the risk and proceed without additional safeguards
Mitigate the risk by implementing a compensating control
Deploying a web application firewall rule does not eliminate the underlying SQL injection vulnerability; instead, it reduces the likelihood of exploitation by adding a compensating control. This is a form of risk mitigation, where the team lowers the risk's impact or probability while planning a later remediation. Re-engineering the code would be remediation, purchasing insurance would be risk transfer, and doing nothing would be risk acceptance, none of which match the scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a compensating control?
Open an interactive chat with Bash
How does a web application firewall mitigate SQL injection?
Open an interactive chat with Bash
Why is risk mitigation chosen over remediation in this scenario?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .