ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
To validate security controls in a payment microservice before go-live, you must create simulation-based test cases that closely mirror production traffic patterns without exposing customer cardholder data. Which approach BEST satisfies this requirement?
Rely solely on unit tests that mock the payment gateway's external dependencies within the development IDE.
Generate synthetic payment requests that follow production traffic patterns and tokenize all cardholder data before they enter the test environment.
Enable verbose logging in production for one day, then copy the resulting log files into the test environment for analysis.
Replay sanitized production web-server logs against the microservice in a flat, non-segmented test network.
Using synthetic transactions that copy production request rates and message structures while replacing sensitive fields with tokenized or otherwise fictitious values reproduces real data flows, exercise authentication, authorization, and cryptographic paths, and avoids the compliance risks of moving real cardholder data into test. Replaying raw logs or copying production records-even if partially sanitized-can still leak sensitive information or miss interactive behaviors. Simple unit tests with mocked objects lack full data-flow realism, and enabling verbose logging in production then copying those logs introduces privacy and security concerns rather than providing a true simulation of live traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is tokenization and why is it important in testing payment systems?
Open an interactive chat with Bash
How do synthetic transactions help replicate production traffic patterns?
Open an interactive chat with Bash
Why is using sanitized production web-server logs not recommended for testing?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .