ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your organization is evaluating a Software-as-a-Service (SaaS) vendor that will handle sensitive customer data. To ensure the provider's security events can be monitored alongside internal systems, which contractual requirement will MOST help the security operations team integrate the vendor's logs into the corporate SIEM?

  • Logs shall be exported in a recognized, machine-readable format (e.g., CEF or JSON) and transmitted securely to the buyer's SIEM in near real time.

  • The provider shall email daily PDF security summaries to the buyer's security team.

  • The provider shall grant read-only access to its web-based monitoring dashboard upon request.

  • The service shall maintain 99.9 percent availability with a four-hour mean time to repair.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot