ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a security design review for a microservice-based REST API, the team must decide how client sessions will be represented. Which proposed solution adheres most closely to the economy of mechanism principle?

  • Record each session as an entry on a consortium blockchain so all microservices can independently verify token provenance.

  • Embed user attributes in a signed and encrypted JWT that contains nested claims and uses different rotating keys for every microservice.

  • Invent a proprietary token format that applies custom compression and a home-grown checksum algorithm before transmission.

  • Issue short, opaque session IDs stored in an in-memory data store and validate them using a standard, widely tested session-management library.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot