ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A DevSecOps team must enable employees to access five internal microservices. To apply the economy of mechanism principle while also reducing password fatigue for users, which authentication approach is MOST appropriate?

  • Require users to maintain separate usernames and passwords for every microservice but enforce identical password complexity rules.

  • Integrate all services with a centralized SAML/OIDC-based single sign-on service provided by a well-vetted identity provider.

  • Store each user's credentials in an encrypted environment file on every host and have services read the file locally at startup.

  • Develop a distinct custom authentication library for each microservice, using different encryption algorithms to diversify defenses.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot