ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While reviewing a draft of an application's user guide, you discover a troubleshooting section that tells administrators to set a hidden environment variable which temporarily disables the product's authentication checks so that verbose debug logs are written. No compensating controls are mentioned. What is the MOST appropriate action before the guide is released to customers?

  • Leave the instruction in place but add a note telling administrators to re-enable authentication immediately after collecting logs.

  • Escalate the issue, work with engineering to provide a secure, documented diagnostic method that keeps authentication intact, and revise the guide accordingly.

  • Remove the entire troubleshooting instruction and direct customers to contact support whenever detailed logs are needed.

  • Approve the guide unchanged because the variable is undocumented and only skilled users will find it.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot