ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your DevSecOps team's automated security scan detects a high-severity SQL injection flaw in a microservice that is already live. You manually confirm the vulnerability exists. To guarantee it is followed from discovery through verified fix, what should you do next?

  • Create an entry in the organization's centralized vulnerability or defect tracking system, include severity and affected components, and assign it to the responsible team.

  • Notify senior management of the issue and wait for explicit direction before taking any additional action.

  • Deploy an emergency web application firewall rule to block the suspected attack vector and mark the scan finding as resolved.

  • Roll back the service to the previous release and omit the discovery from internal documentation to avoid external disclosure.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot