ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During final regression testing for a web application that is supposed to go live in two days, the security team discovers a SQL-injection flaw that allows privilege escalation and is trivially exploitable. Break/build criteria state that any critical vulnerability must be resolved before production release. What action best aligns with secure SDLC practice when assessing the impact of this finding on product management and the release schedule?
Note the issue for a post-release hotfix so the launch date remains unchanged.
Reclassify the finding as medium because it was discovered internally and proceed with deployment.
Disable the affected function in the automated tests to avoid blocking the release and add the defect to the backlog.
Fail the build, inform product management, and reschedule the release after the vulnerability is remediated and retested.
Because the flaw is critical and violates the project's break/build criteria, the correct response is to fail the current build, notify product management, and re-plan the release after the defect is fixed and retested. This approach ensures that an unacceptable risk is not pushed to production while still giving product management the information needed to adjust timelines. Accepting the risk, downgrading its severity, or hiding the vulnerable feature might preserve the schedule but ignores established policy and leaves the organization exposed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SQL injection, and why is it critical in web applications?
Open an interactive chat with Bash
What is secure SDLC, and how does it prioritize handling vulnerabilities?
Open an interactive chat with Bash
What are break/build criteria, and why are they important in software development?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .