ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While preparing the security test strategy for a new online banking platform, you must verify that its token-based authentication and authorization mechanisms remain effective and performant when the number of simultaneous users rises from 10,000 to 100,000 during seasonal peaks. Which testing activity should you include to evaluate the scalability of these security controls?

  • Apply static code analysis to the authentication module to detect improper input validation.

  • Run fuzzing campaigns that mutate API request parameters in search of authorization bypass conditions.

  • Perform stress and load tests that simulate high volumes of concurrent logins and API calls, monitoring authentication and authorization performance.

  • Review the role-based access control matrix to confirm least-privilege assignments.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot