ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During decommission of a customer-facing web service, you discover several API keys still grant backend access for integration partners. Under the organization's EOL policy, which action best satisfies the credential removal requirement before servers are powered down?

  • Generate new stronger API keys and send them to partners marked as inactive until re-enablement is needed.

  • Disable network routes to the backend so the keys can no longer reach their targets, leaving them in place for audit purposes.

  • Revoke every remaining API key and delete their records from configuration repositories and partner portals.

  • Encrypt the existing keys at rest and move them to long-term archives with limited administrative access.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot