ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While negotiating a security-specific SLA for a newly procured payment processing API, which clause provides the most direct control over the vendor's speed in eliminating discovered high-severity vulnerabilities before they can be exploited in production?

  • Include a requirement that high-severity vulnerabilities are remediated within a defined maximum mean time to remediate (MTTR).

  • Specify a 99.95 percent minimum service availability throughout the contract term.

  • Require the supplier to provide summary reports of independent penetration tests every month.

  • Mandate the use of TLS 1.2 or higher to encrypt all data in transit between systems.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot