ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A DevOps team is building a new CI/CD pipeline for its container-based web service. Unit and functional tests already execute on every commit. Management wants any code that introduces high-severity security flaws to be rejected automatically, without waiting for manual review. Which action best enables continuous security testing that meets this objective?

  • Schedule an external penetration test every quarter and remediate any critical findings before the next release.

  • Invoke an automated static application security testing (SAST) scan on each commit and configure the build to fail if it reports high-severity issues.

  • Run a dynamic vulnerability scanner against the production environment each night and email reports to the security team.

  • Insert a manual security code review step after integration tests pass, allowing senior developers to approve merges.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot