ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During requirements analysis for a new account-data export endpoint, the team documents a misuse case stating: "An attacker guesses another user's export URL and downloads their CSV." Which security requirement most directly counters this misuse scenario?
Record every export attempt in an audit log and trigger alerts for abnormal patterns.
Restrict the maximum size of CSV exports to reduce resource consumption.
Perform a server-side authorization check on each export request to verify the requester is entitled to the specific account data.
Enforce TLS for all export traffic to prevent eavesdropping on data in transit.
The threat is unauthorized access to another user's exported data after discovering or guessing the endpoint URL. The most direct mitigation is to enforce a fine-grained authorization check on every export request to confirm the requester owns-or is explicitly permitted to access-the data being generated. While HTTPS, logging, or limiting file size are valuable controls, they do not stop an authenticated attacker from successfully downloading someone else's information once the URL is known. Proper per-request authorization blocks the attack outright by ensuring data is only returned when access rights match the targeted resource.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are misuse cases in security requirements analysis?
Open an interactive chat with Bash
What is server-side authorization and how does it work?
Open an interactive chat with Bash
Why doesn't enforcing TLS prevent unauthorized access in this scenario?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .