ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your organization is decomposing a legacy web app into microservices exposed through a common API gateway. The security team must provide uniform authentication across services, enable Single Sign-On for users from partner domains, and avoid copying auth code into every service. Which security architecture pattern should they adopt?

  • Rely on network segmentation and IP allow-lists at the VLAN level to authenticate and authorize all service requests.

  • Maintain a shared database of user credentials that every microservice queries to authenticate incoming requests.

  • Implement a federated identity solution that issues security tokens consumed by the API gateway and propagated to each microservice.

  • Embed username-password authentication logic directly within every microservice and validate credentials locally.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot