ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During backlog refinement, a product owner adds the user story: "As a new employee, I must be required to change my system-generated password at first login so my account is secure." According to secure SDLC terminology, how should this requirement be categorized?
It is a non-functional continuity requirement related to disaster recovery.
It is a non-functional operational requirement concerning how the system runs.
It is a non-functional deployment requirement governing installation.
It is a functional security requirement that modifies the authentication workflow.
Forcing a user to change a system-generated or default password dictates a concrete behavior the application must perform during its authentication workflow. Because it defines what the software must do from a security perspective, it is a functional security requirement. Non-functional operational, continuity, and deployment requirements describe how the system should run, be recovered, or be installed; they do not specify interactive security functionality.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between functional and non-functional requirements?
Open an interactive chat with Bash
Why is forcing password changes considered a functional security requirement?
Open an interactive chat with Bash
What are examples of non-functional security requirements?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .