ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a production release, your organization wants to enforce segregation of duties through multi-party control. Which of the following practices BEST meets this goal?
Developers are blocked from viewing production logs unless they open a support ticket.
Two engineers must independently authenticate to reveal separate portions of the production signing key before code can be signed.
A single release manager uses their personal hardware security token to sign and deploy the build.
The CI/CD pipeline automatically deploys code to production once automated tests succeed.
Multi-party control requires more than one individual to authorize or perform a critical action. Requiring two engineers to supply separate authentications that each reveal part of the signing key enforces dual control (split knowledge), meaning no single person can sign and release code alone. A sole release manager with a hardware token, automated deployment without human approval, or restricting access to production logs do not involve multiple people jointly authorizing the critical signing action and therefore do not satisfy multi-party control for segregation of duties.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is multi-party control, and why is it important in production releases?
Open an interactive chat with Bash
What is dual control or split knowledge in security practices?
Open an interactive chat with Bash
How does enforcing segregation of duties protect the software development lifecycle?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .