ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your company must confirm that a potential SaaS vendor actually follows secure software development practices before signing a contract. Which of the following pieces of evidence would provide the strongest, most objective basis for concluding that the vendor's SDLC complies with recognized security standards?
A recent independent SOC 2 Type II report that maps the vendor's software development life cycle to recognized security control frameworks.
A signed letter from the vendor's sales team stating that they follow ISO/IEC 27034 secure coding guidelines.
The latest external penetration-test summary showing no critical vulnerabilities in the production environment.
Copies of the vendor's internal code-review checklist templates used by development teams.
An independent, recently completed SOC 2 Type II (or comparable) assurance report provides the highest level of confidence that a supplier follows documented secure development practices. Such reports are issued by a qualified third-party auditor after reviewing the vendor's policies, developer training, code control, testing, and release processes over a sustained period, and they map the evidence collected to established security control criteria (for example, AICPA Trust Services Criteria or mappings to frameworks like NIST SSDF). A vendor marketing statement is merely self-attested and unaudited. Results from a single penetration test are point-in-time and assess only the deployed application, not the underlying SDLC processes. Internal code-review checklists can be helpful, but without external validation they do not demonstrate actual, consistent adherence to secure development practices. Therefore, the third-party audit report is the most reliable source for verifying compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a SOC 2 Type II report?
Open an interactive chat with Bash
What does the NIST SSDF framework include?
Open an interactive chat with Bash
How is a penetration test different from an SDLC audit?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .