ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While updating the security requirement traceability matrix for a new payroll web service, a developer records: "All employee records shall be encrypted at rest using AES-256 and keys rotated at least every 90 days without causing service interruption." According to security requirement categories, this statement is best classified as which type of requirement?

  • A misuse case describing an attack scenario.

  • A non-functional security requirement that specifies a quality attribute.

  • A functional security requirement expressed as a user-facing feature.

  • A business continuity requirement unrelated to security.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot