ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a design review, a CSSLP is tasked with defining the minimum set of application events that must be captured and retained for security monitoring. Which event category is most critical to include in the application's log records?
Browser-stored encrypted session cookies captured at each request
Successful and failed user authentication attempts, including user ID and timestamp
Client-side mouse movement events collected for user-experience analytics
Routine garbage-collection cycles executed by the application runtime
Authentication attempts-both successful and failed-provide definitive evidence of who tried to access the system and when, making them indispensable for detecting brute-force attacks, credential stuffing, and account misuse. Capturing the user identifier and timestamp supports correlation with other security data and incident response. Routine garbage-collection messages, user-interface mouse movements, and storing encrypted session cookies offer negligible value for security monitoring and may add noise or expose sensitive data. Therefore, logging authentication events is the highest priority for a secure audit trail.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why are authentication attempts considered the most critical events to log?
Open an interactive chat with Bash
What is brute-force and credential-stuffing, and why are they significant for security monitoring?
Open an interactive chat with Bash
Why is logging browser-stored cookies or mouse movements not valuable for security monitoring?
Open an interactive chat with Bash
Why are successful and failed authentication attempts critical to security monitoring?
Open an interactive chat with Bash
What is credential stuffing, and how does logging authentication attempts help detect it?
Open an interactive chat with Bash
How does correlating authentication logs with other security data improve incident response?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .