ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During final security testing, you review the administrator installation guide for a new payroll application and notice it never instructs administrators to disable the default Guest accounts that remain enabled after setup. To meet organizational requirements for verifying and validating security documentation, what is the most appropriate next step before release?
Approve the release because experienced administrators will know to disable unused accounts even without documentation.
Silently remove the Guest accounts in the code but leave the documentation unchanged to avoid delaying the release.
Log a documentation defect and require the guide and installer to be updated to direct administrators to disable the Guest accounts before shipping.
Release on schedule and publish an out-of-band knowledge-base article later that explains how to disable the Guest accounts.
Organizational policy requires security documentation to be complete, accurate, and available at release so deployers can configure the product securely. Leaving default Guest accounts active in production represents a serious vulnerability, and failing to document the need to disable them is a critical documentation defect. The correct response is to file a release-blocking defect so the installer and administrator guide are updated to instruct administrators to disable (or remove) the Guest accounts before shipping. Releasing without fixing the guides, relying on administrator intuition, issuing post-release knowledge-base articles, or silently changing code without matching documentation all violate the organization's verification and validation requirements and could leave systems exposed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is it important to disable Guest accounts?
Open an interactive chat with Bash
What are verification and validation requirements in security documentation?
Open an interactive chat with Bash
What is a release-blocking defect?
Open an interactive chat with Bash
Why are default Guest accounts considered a serious security vulnerability?
Open an interactive chat with Bash
What are verification and validation requirements in security documentation?
Open an interactive chat with Bash
What is a release-blocking defect, and why is it critical to address?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .