ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A development team building a SaaS CRM will host EU customer records in a U.S. data center. When identifying compliance requirements, which feature must be captured because it is explicitly mandated by the GDPR rather than by industry or company policy?

  • Retain detailed audit logs for a minimum of seven years to support potential litigation holds.

  • Provide a mechanism for data subjects to request erasure of their personal data at any time.

  • Encrypt all stored data using a FIPS 140-2 Level 3 validated hardware security module.

  • Undergo an annual SOC 2 Type II audit covering security and availability controls.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot