ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is negotiating a contract for a new customer-facing application that will run on a Software-as-a-Service (SaaS) platform. To document the shared responsibility model, you must specify which security testing tasks remain yours and which belong to the provider. Which testing activity should remain solely the customer's responsibility?
Conducting third-party certification audits of the provider's physical data centers
Performing penetration tests of custom API integrations developed by the customer to consume the SaaS service
Running vulnerability scans against the SaaS provider's multi-tenant application stack
Applying operating-system patches to the SaaS platform's virtual machines
In a SaaS relationship the provider owns and operates the application stack, platform, and underlying infrastructure, so vulnerability scanning of that stack, operating-system patching, and data-center audits fall under the provider's scope. The customer, however, is still accountable for security of any code it writes to interact with the service, including penetration testing of custom API integrations. Keeping this responsibility ensures that weaknesses introduced by customer-developed components are discovered without violating the provider's rules for testing its own environment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the shared responsibility model in SaaS?
Open an interactive chat with Bash
Why is penetration testing of custom API integrations important?
Open an interactive chat with Bash
What are the rules for testing a SaaS provider's environment?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .