ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During security testing of a payment microservice in a staging cluster, you must confirm that the service fails safely if its hardware security module (HSM) suddenly becomes unreachable. Which testing action represents a targeted fault-injection test aimed at exercising this specific failure mode?

  • Intercept the microservice's calls to the HSM and programmatically force each request to time out before a response is returned.

  • Launch a high-volume set of random, malformed TLS handshake messages at the microservice to see how it handles unexpected input.

  • Shut down the microservice's network interface card to observe how it behaves when all outbound traffic is blocked.

  • Perform a static code review to look for unhandled exceptions around every HSM API invocation.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot