ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A SaaS provider must update its terms of service to satisfy GDPR and similar laws that require the company to tell subscribers how their personal data will be used. Which statement would MOST directly fulfill this transparency obligation?

  • A concise explanation of why each category of personal data is processed and the types of external parties that may receive it.

  • The contact address of the data protection officer and instructions for submitting subject access requests.

  • A description of the encryption algorithms and key-management practices that protect stored personal data.

  • A list of every personal data element collected and the period for which each element will be retained.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot