ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
To reduce the chance of developers unintentionally bypassing access control, a DevSecOps engineer recommends adopting declarative security for an internal microservice. Which technique best aligns with this recommendation?
Add code to log and re-throw security exceptions whenever input validation fails
Encrypt all inter-service requests with TLS 1.3 and mutual authentication
Embed role checks in each controller method using explicit if-else logic
Manage endpoint authorization rules in an external YAML policy file loaded by the service at runtime
Declarative security keeps authorization rules outside the business logic so the runtime can enforce them consistently. Storing endpoint-to-role mappings in an external YAML (or XML/JSON) policy file lets the service container apply access controls automatically at startup. Placing if-else role checks in code, adding exception handlers, or enabling TLS are useful practices, but they are imperative checks or transport protections-not an external, configuration-driven security model characteristic of declarative security.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is declarative security?
Open an interactive chat with Bash
Why is using an external YAML policy file beneficial for security?
Open an interactive chat with Bash
How is declarative security different from TLS encryption?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .