ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security design review, you discover that a new microservice accepts any call originating from the corporate subnet without additional checks. To better adhere to Zero Trust and least privilege principles, which architectural change should you recommend?
Combine the microservice with the caller into a single internal monolithic application to eliminate network traffic.
Enforce a 16-character minimum length for all administrator passwords.
Place the microservice behind the existing perimeter firewall inside a more restrictive VLAN.
Require mutual TLS with per-request validation of short-lived, signed access tokens between services.
Zero Trust assumes no implicit trust based on network location. Every request-internal or external-must be explicitly authenticated and authorized. Implementing mutual TLS and requiring each call to present a short-lived, signed access token forces the service to verify the caller's identity and permissions every time, enforcing least privilege. Merely moving the service to a VLAN or behind a perimeter firewall continues to rely on network-based trust. Increasing password complexity addresses credential strength for humans, not service-to-service authorization, and merging the microservice into a monolith removes isolation rather than improving granular access control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Zero Trust and how does it differ from traditional security models?
Open an interactive chat with Bash
What is mutual TLS, and why is it necessary in this scenario?
Open an interactive chat with Bash
How do short-lived, signed access tokens improve security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Concepts
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .