ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

After merging a critical security patch into the main branch of a cloud-hosted application, the DevSecOps team must decide what to do next. Following a secure patch release process that balances speed with safety, which action should they take before allowing the pipeline to promote the build to production?

  • Tag the patched commit as a hotfix and immediately generate production images for blue-green deployment without additional checks.

  • Archive the patched code and wait for the next quarterly change review meeting to schedule production deployment.

  • Disable all automated tests to accelerate the pipeline and deploy the patched build directly to production.

  • Trigger the automated security and regression test suite in a staging environment and require all tests to pass before production deployment.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot