ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a requirements workshop, the security architect is asked to label several backlog items. Which of the following proposed backlog items is most clearly a non-functional security requirement rather than a functional one?

  • If a user enters an incorrect password five times, the account shall be locked for 30 minutes.

  • All sensitive data transmitted between components shall be encrypted using only TLS 1.3.

  • The system shall display the previous successful login time immediately after authentication.

  • Users shall be able to generate a one-time passcode to confirm high-risk transactions.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot