ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a secure‐update project, you must ensure that desktop clients can verify both the origin and the untampered state of each new executable they download from the company's server. Which control is the most effective way to meet this requirement?

  • Digitally sign each release with a trusted code-signing certificate and have clients verify the signature before execution

  • Publish a separate SHA-256 checksum that users can compare after downloading

  • Apply code obfuscation to make the binary harder to analyze

  • Distribute the files over HTTPS to prevent interception during download

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot