ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While defining privacy requirements for a new mobile shopping app that will collect customer email addresses, the project team must ensure compliance with both GDPR and U.S. CAN-SPAM regulations. Which requirement most effectively protects user rights over marketing communications and reduces potential regulatory penalties?

  • Treat acceptance of the terms of service as consent for marketing; users may opt out by emailing customer support.

  • Use a pre-ticked checkbox for consent and require users to log in to a separate website to change marketing preferences.

  • Collect consent through an unchecked box the user must actively select and provide an in-app preferences screen that lets the user withdraw consent at any time, with withdrawals honored within 10 days.

  • Automatically subscribe every registered user to promotional emails and include an unsubscribe link in each message.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot