ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During preparation for an external pen test, your team must develop attack surface validation test cases for a newly deployed RESTful microservice that will be exposed to business partners. Which single test case would most effectively validate the service's external attack surface before release?

  • Verify that input validation constrains payload size to typical usage limits to prevent buffer overflows.

  • Run randomized fuzzing against internal helper functions that are only invoked by backend microservices.

  • Confirm that the cryptographic libraries in the codebase rely solely on FIPS 140-2 validated algorithms.

  • Enumerate every HTTP verb on each endpoint and attempt unauthenticated or unauthorized calls, including rarely used methods like OPTIONS and TRACE.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot