ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During abuse case analysis for a social media web app that lets members upload profile images, the analyst records the scenario "attacker uploads a 2-GB file to consume backend storage and impact availability." Which security requirement most directly mitigates this specific misuse case?
The application shall embed a visible watermark on every uploaded image before storing it.
The application shall compute a SHA-256 hash of each uploaded file and log it for integrity verification.
The application shall submit every uploaded file to an anti-malware engine before making it available to users.
The application shall enforce a maximum upload size of 5 MB and reject any larger files.
The documented abuse case focuses on exhausting server storage by submitting an excessively large file. A requirement that limits the maximum upload size directly removes the attacker's opportunity, making the threat scenario impossible to execute. Watermarking, hashing, and malware scanning protect other aspects of image handling (copyright, integrity, or malicious content) but do not prevent a storage-exhaustion attack because they still allow the large file to be stored first.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an abuse case analysis?
Open an interactive chat with Bash
Why is limiting file upload size important for security?
Open an interactive chat with Bash
What is a SHA-256 hash, and how does it work for file integrity?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .