ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
You are leading the security V&V effort for a healthcare mobile app. The independent test team has completed security verification and discovered that the encryption module fails to enforce FIPS-validated ciphers. The agreed break/build criteria state any mandatory control failure halts release. What is the most appropriate next step?
Proceed with validation testing in parallel while development creates a hotfix to preserve the release schedule.
Reject the build and send it back to development for remediation before any further validation activities occur.
Publish the issue in the release notes and deploy the app, relying on network controls to mitigate the risk.
Ask the V&V team to perform a business risk assessment and approve an interim authority to operate if the risk is low.
Break/build criteria are predefined thresholds that determine whether a build may proceed. Because the encryption defect violates a mandatory regulatory control, the criteria dictate that the build must be stopped and returned to development. Continuing with validation tests, releasing with compensating controls, or having the test team accept the business risk would all override the formally established gate and defeat the purpose of independent verification and validation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does FIPS-validated mean in the context of encryption modules?
Open an interactive chat with Bash
What is the role of break/build criteria in software development?
Open an interactive chat with Bash
Why is independent verification and validation (V&V) important in secure software development?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .