ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While reviewing the operational risk register for a newly deployed CRM application, you note that all end users completed a mandatory annual security awareness course, but system administrators only receive the same generic training and no role-specific instruction. Which risk is most heightened by this training imbalance, and what is the most effective mitigation?

  • Higher risk of malware infection through phishing; deploy advanced email filtering and multifactor authentication.

  • Greater exposure to injection flaws in the application; require all developers to complete secure-coding courses.

  • Elevated chance of service outages from unpatched software; enforce an automated patch-management program.

  • Increased likelihood of privilege misuse by administrators; implement role-based security training tailored to privileged roles.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot