ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a security design review, you discover that a new microservice accepts any call originating from the corporate subnet without additional checks. To better adhere to Zero Trust and least privilege principles, which architectural change should you recommend?

  • Enforce a 16-character minimum length for all administrator passwords.

  • Place the microservice behind the existing perimeter firewall inside a more restrictive VLAN.

  • Require mutual TLS with per-request validation of short-lived, signed access tokens between services.

  • Combine the microservice with the caller into a single internal monolithic application to eliminate network traffic.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot