ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an architecture review of a browser-based stock trading RIA that relies on a persistent WebSocket connection for real-time quotes and order submission, the team must address security risks introduced by constant connectivity. Which control BEST mitigates these specific risks?
Implement idle session timeouts and heartbeat monitoring to automatically terminate inactive WebSocket channels.
Place the WebSocket server behind a stateless load balancer configured to drop any connection lasting longer than one minute.
Enable database transparent data encryption to protect trade records stored on disk.
Require complex passwords and multifactor authentication during user logon to the trading application.
Persistent connections can be abused if they remain open indefinitely: attackers may hijack dormant sessions, and unused connections consume server resources needed for other clients. Implementing idle-session timeouts combined with periodic heartbeat or ping/pong messages lets the server quickly detect inactivity or dropped clients and close or renegotiate the channel, limiting the window for hijacking, avoiding resource exhaustion, and ensuring only legitimate, active clients retain long-lived connectivity. Strong authentication and data-at-rest encryption are important but do not directly mitigate the unique exposure created by always-on WebSocket channels, while forcing a stateless load balancer to terminate long-lived sessions would break required functionality without addressing security concerns effectively.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a WebSocket connection?
Open an interactive chat with Bash
Why are idle-session timeouts important for WebSocket connections?
Open an interactive chat with Bash
What is heartbeat monitoring in WebSocket connections?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .