ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a pre-award audit, you must confirm that a prospective supplier actually applies secure coding controls in line with your NIST SSDF-aligned policy, not just documents them. Which evidence most directly demonstrates active adherence to those controls?

  • A letter from the supplier's CTO affirming compliance with secure coding guidelines

  • Detailed SAST reports for recent builds that include identified findings and their remediation status

  • A current ISO 9001 quality management certification for the supplier's development facility

  • The supplier's documented software development life-cycle (SDLC) policy outlining security objectives

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot