ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

To avoid per-call fees and request limits while verifying authentication, input validation, and error handling in a new e-commerce checkout service that invokes a third-party tax API, the team will test in staging. Per CSSLP guidance on simulated testing, which approach best meets this need without calling the live provider?

  • Import a recent production database snapshot into QA and run manual functional tests against the live tax API.

  • Commission an external black-box penetration test against the production site to uncover exploitable flaws in the checkout process.

  • Create virtual instances of the tax-calculation service in a staging environment and execute a suite of automated synthetic checkout transactions covering normal and error paths.

  • Rely solely on static code analysis of the checkout module to identify input-handling vulnerabilities before release.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot