ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is contracting a third-party microservice to run in its cloud tenant. Internal policy requires that all security events from the service be correlated in the enterprise SIEM. Which contractual clause will best ensure this requirement is met?
Require the supplier to maintain a current ISO/IEC 27001 certification during the contract term.
Require the supplier to deliver quarterly vulnerability assessment summaries for review by the security team.
Require the service to export security event logs in an industry-standard format (e.g., CEF or JSON) over a secure transport such as TLS-protected syslog or API for direct SIEM ingestion.
Require the service to encrypt all stored data using AES-256 or stronger algorithms.
Stipulating that the supplier must export security logs in a standard format-such as CEF or JSON-over a secure channel (TLS-protected syslog or authenticated REST API) directly enables SIEM ingestion and correlation.
The other clauses fall short:
Quarterly vulnerability summaries are periodic reports, not live event feeds.
ISO/IEC 27001 certification shows general security maturity but does not mandate log forwarding.
AES-256 encryption protects stored data but has no bearing on real-time event export.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Security Information and Event Management (SIEM) system?
Open an interactive chat with Bash
What is the significance of using industry-standard formats like CEF or JSON for log exports?
Open an interactive chat with Bash
What is the role of secure transport protocols like TLS in log forwarding?
Open an interactive chat with Bash
What is CEF (Common Event Format)?
Open an interactive chat with Bash
What is a SIEM and how does it work?
Open an interactive chat with Bash
Why is log transport security important in cloud services?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .