ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While updating the risk register for a new online payment platform, a security engineer must label each finding as a technical or business risk. Which of the following represents a business risk rather than a technical risk?
Use of an outdated cryptographic library that enables attackers to force insecure TLS downgrade attacks
Exposure of cardholder data through SQL injection caused by missing input validation in database queries
Lack of a server-hardening baseline resulting in multiple unpatched services running on production hosts
Potential regulatory fines and revocation of the merchant license if the platform fails to meet PCI DSS requirements
Business risks describe potential impacts on the organization's objectives-such as financial loss, legal penalties, or reputational damage-whereas technical risks focus on flaws in technology or implementation details. Fines and loss of a merchant license for PCI DSS non-compliance threaten revenue and the company's ability to operate, making this a business risk. The other options describe weaknesses in code, configuration, or cryptography; these are technical risks because they pertain to how the system is built or operated rather than the broader organizational consequences.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS and why is it important for online payment platforms?
Open an interactive chat with Bash
How can a risk be differentiated as a business risk versus a technical risk?
Open an interactive chat with Bash
What are some best practices for managing business risks like PCI DSS non-compliance?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .