ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During an architecture review, you discover that an order-processing service will invoke an external payment gateway's REST API over TLS and parse its JSON response to update transaction status. To mitigate security risks introduced by this upstream dependency, which design measure should you add?

  • Allow the gateway to write payment results directly into the backend database to streamline processing.

  • Place the gateway in the same network segment to reduce latency and firewall traversal.

  • Disable mutual TLS and rely on username/password authentication to simplify certificate management.

  • Validate all JSON responses from the gateway against a strict schema before any business logic executes.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot