ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a sprint planning session, the security architect is asked to label the following backlog items. Which item represents a functional security requirement rather than a non-functional security attribute?
All external API traffic shall be encrypted using TLS 1.3 or higher.
The application shall record every administrative action, including user ID and timestamp, in an immutable audit log.
The system shall maintain 99.9 % uptime during business hours.
The solution shall comply with OWASP Application Security Verification Standard (ASVS) Level 2.
A functional security requirement describes an action the software must perform to protect itself or its data. Requiring the application to record every administrative action with the associated user ID and timestamp specifies a discrete security capability the system must provide, so it is functional. Conforming to OWASP ASVS Level 2, mandating TLS 1.3 for all HTTPS connections, and meeting a 99.9 % availability target describe quality levels or standards the solution must meet; these are non-functional ("ility") requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between functional and non-functional security requirements?
Open an interactive chat with Bash
What is OWASP ASVS Level 2?
Open an interactive chat with Bash
Why is TLS 1.3 a critical security attribute?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .