ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While negotiating a security-specific SLA for a newly procured payment processing API, which clause provides the most direct control over the vendor's speed in eliminating discovered high-severity vulnerabilities before they can be exploited in production?
Include a requirement that high-severity vulnerabilities are remediated within a defined maximum mean time to remediate (MTTR).
Specify a 99.95 percent minimum service availability throughout the contract term.
Require the supplier to provide summary reports of independent penetration tests every month.
Mandate the use of TLS 1.2 or higher to encrypt all data in transit between systems.
An SLA clause that sets an explicit maximum mean time to remediate (MTTR) high-severity vulnerabilities obligates the supplier to fix critical issues within an agreed-upon window. This directly governs how quickly risk is reduced. Penetration-testing reports, uptime targets, and encryption requirements are valuable controls, but none dictate how soon identified vulnerabilities must be resolved, leaving remediation timing to the vendor's discretion.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is MTTR and why is it important in an SLA?
Open an interactive chat with Bash
Why are penetration-testing summary reports less effective for controlling remediation speed?
Open an interactive chat with Bash
How does mandating TLS encryption differ from controlling vulnerability remediation?
Open an interactive chat with Bash
What is MTTR in the context of security-specific SLAs?
Open an interactive chat with Bash
Why are penetration-testing reports less effective than MTTR clauses in controlling vulnerability remediation timelines?
Open an interactive chat with Bash
How does TLS encryption differ from an MTTR clause in securing APIs?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .