ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While planning the secure SDLC for a card-processing web application, the team must identify PCI DSS 4.0 activities that are compulsory rather than merely recommended. Which action is an explicit PCI DSS requirement related to software development?
Store compiled payment software with an approved external code-escrow service for at least five years.
Run dynamic application security tests on all Internet-facing components once per year or after significant changes.
Review all custom application code, by an individual independent of the code author, before it is promoted to production.
Hold a dedicated Agile retrospective after every sprint to capture security lessons learned.
PCI DSS requires that every piece of custom code affecting cardholder data be reviewed by someone other than the code's original author before the software is released. The review must verify that secure coding practices were followed and that any vulnerabilities were corrected (PCI DSS v4.0, Requirement 6.2.3/6.2.4). Annual dynamic testing, Agile retrospectives, and mandatory code escrow are not prescribed by the standard; they may be useful practices but they are not explicitly required.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS and why is it important?
Open an interactive chat with Bash
What is the purpose of reviewing custom application code in PCI DSS compliance?
Open an interactive chat with Bash
What are dynamic application security tests, and why aren't they explicitly required by PCI DSS?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .