ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During verification and validation of the draft administrator guide for a payroll web service, you must flag any content that could undermine security. Which documentation issue requires remediation because it could disclose sensitive implementation details to an attacker even if the software itself is secure?
The troubleshooting section includes complete stack-trace examples that show class names and line numbers.
The guide states the service uses HTTPS on port 443 for all external traffic.
The release notes list the minimum browser versions the application supports.
An operations checklist reminds administrators to rotate encryption keys once a year.
Exposing full stack traces in documentation reveals internal class names, file paths, and line numbers that attackers can use to refine exploits or discover unpatched libraries. Security guidance such as key-rotation checklists, HTTPS usage notes, or supported browser versions do not expose actionable internal details and therefore do not constitute a security documentation defect.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is exposing stack traces in documentation a security risk?
Open an interactive chat with Bash
What is a stack trace, and why is it included in troubleshooting sections?
Open an interactive chat with Bash
How can troubleshooting documentation maintain security while being useful?
Open an interactive chat with Bash
Why is exposing full stack traces in documentation a security risk?
Open an interactive chat with Bash
What is the recommended alternative to including full stack traces in documentation?
Open an interactive chat with Bash
Why is mentioning HTTPS usage and encryption key rotation not a documentation defect?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .