ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During contract negotiations for a cloud-hosted authentication service, your organization insists that the provider stream security logs to your SIEM and apply critical security patches within an agreed period. Which contractual instrument is BEST suited to formalize and enforce these ongoing monitoring and vulnerability-response requirements?
A non-disclosure agreement outlining confidentiality and proprietary information handling
An intellectual-property assignment transferring ownership of custom-developed code
A code-escrow clause ensuring release of source code if the supplier becomes insolvent
A service-level agreement that specifies log delivery formats, frequency, and remediation timelines
A service-level agreement (SLA) is specifically intended to define measurable performance and service requirements that the supplier must meet throughout the life of the contract. Security-related SLAs commonly spell out log-generation formats, transmission frequency to the customer's SIEM, maximum time to notify of incidents, and deadlines for releasing patches or mitigations. A non-disclosure agreement focuses on confidentiality, not operational security obligations. A code-escrow clause only guarantees source-code availability if the vendor fails to support the product, and an intellectual-property assignment governs ownership rights, not day-to-day security monitoring or response expectations. Therefore, the SLA is the most appropriate vehicle for enforcing continuous logging and vulnerability-response commitments.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Service-Level Agreement (SLA)?
Open an interactive chat with Bash
Why is an SLA better suited than an NDA for security-related commitments?
Open an interactive chat with Bash
What is a Security Information and Event Management (SIEM) system?
Open an interactive chat with Bash
What is an SLA in the context of cloud services?
Open an interactive chat with Bash
Why is log delivery to a SIEM essential in security monitoring?
Open an interactive chat with Bash
What are the key components of a security-focused SLA?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .