ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During security testing of a payment microservice in a staging cluster, you must confirm that the service fails safely if its hardware security module (HSM) suddenly becomes unreachable. Which testing action represents a targeted fault-injection test aimed at exercising this specific failure mode?
Intercept the microservice's calls to the HSM and programmatically force each request to time out before a response is returned.
Launch a high-volume set of random, malformed TLS handshake messages at the microservice to see how it handles unexpected input.
Shut down the microservice's network interface card to observe how it behaves when all outbound traffic is blocked.
Perform a static code review to look for unhandled exceptions around every HSM API invocation.
Fault injection deliberately introduces faults at the point where they would naturally occur so the team can observe error-handling behavior. Intercepting HSM API calls inside the microservice and forcing them to time out directly emulates the condition of an unresponsive HSM, allowing testers to verify graceful degradation and proper exception handling. Generating random TLS handshakes is fuzz testing that focuses on protocol parsing, not device failure. Reviewing source code is static analysis and does not actively introduce a fault. Disabling the microservice's entire network interface disrupts many functions and is closer to a broad resilience or chaos test, not a targeted injection at the HSM dependency.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an HSM and why is it important in security testing?
Open an interactive chat with Bash
How does fault injection differ from chaos testing?
Open an interactive chat with Bash
What is fuzz testing, and why is it not the right choice in this case?
Open an interactive chat with Bash
What is a Hardware Security Module (HSM)?
Open an interactive chat with Bash
What is fault injection testing?
Open an interactive chat with Bash
How does fault injection differ from fuzz testing?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .