ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During an architecture review of a multi-tenant IaaS platform running on commodity x86-64 servers, you are asked to recommend a control that will most effectively reduce the risk that Spectre/Meltdown-style speculative execution attacks could allow one tenant to read privileged or cross-VM memory pages. Which host-level requirement should you specify?

  • Compile all guest workloads with retpoline to eliminate indirect branch speculation.

  • Enable simultaneous multithreading (hyper-threading) and pin each virtual CPU to a dedicated hardware core.

  • Strengthen address space layout randomization (ASLR) and stack canaries in all guest images.

  • Require Kernel Page-Table Isolation (KPTI) to separate user and kernel page tables on both host and guest operating systems.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot