ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During backlog grooming, the team reviews the user story: "As an administrator, I need the application to record every failed login attempt with the timestamp and originating IP address so I can investigate security incidents." When placing this item into the security requirements catalogue, how should it be classified?
As a functional security requirement because it prescribes a concrete system action.
As a non-functional security requirement concerned with audit logging and operational quality.
As a regulatory requirement because laws like PCI DSS require audit trails.
As a business requirement since it originates from an administrator's need.
The story requires the system to produce audit information that supports security monitoring and incident investigation. Audit logging is a quality attribute that specifies how the software must operate (ability to generate and retain specific records), not a business feature that end-users directly invoke. Therefore it is treated as a non-functional security requirement. Business or regulatory drivers may motivate the need, but the catalogue entry itself is recorded as a non-functional requirement. Functional requirements, by contrast, describe user-visible behaviors such as forcing a password change on first login.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are non-functional security requirements?
Open an interactive chat with Bash
How does audit logging support security monitoring?
Open an interactive chat with Bash
What is the difference between functional and non-functional requirements?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .