ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a peer review of newly added payment-processing code, the lead developer proposes walking the group through her own changes while the other two team members merely observe. From a secure software development standpoint, which adjustment would most increase the likelihood of uncovering security flaws during this manual code review?
Provide a formal security checklist and designate a reviewer who did not write the code to facilitate the session.
Allow the original author to drive the session so she can explain complex logic in real time.
Restrict the review to ensuring the code compiles without warnings to minimize meeting time.
Defer the peer review until dynamic application security testing (DAST) flags any runtime defects.
Manual code reviews are most effective when the reviewer is independent of the code's author and uses a structured, security-focused checklist. Independence reduces confirmation bias and the author's tendency to rationalize risky decisions, while a checklist ensures common vulnerability types (e.g., injection, improper error handling) are systematically examined. Merely having the author lead the discussion, limiting the review to successful compilation, or delaying until after dynamic testing all reduce opportunities to spot logic and design-level issues early.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the purpose of a security-focused checklist in manual code reviews?
Open an interactive chat with Bash
Why is it important for the reviewer to be independent of the code's author?
Open an interactive chat with Bash
How does manual code review differ from dynamic application security testing (DAST)?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .