ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is preparing a security testing strategy for a soon-to-be-released mobile banking app and wants to invite external researchers through a public bug-bounty program. Before advertising rewards or recognition, which item should be established first to set clear expectations for researchers and protect both parties?
Announce monetary reward tiers that correspond to CVSS severity ratings.
Publish a vulnerability disclosure policy that details scope, reporting channels, and safe-harbor provisions.
Draft a non-disclosure agreement (NDA) template for researchers to sign before engagement.
Create a public leader-board system to recognize top contributing researchers.
A vulnerability disclosure policy comes before any incentive structure. The policy defines what targets are in scope, how to submit findings, safe-harbor language that protects good-faith research, and the organization's commitments for triage and response. Without this documented framework, setting reward tiers, recognition schemes, or legal agreements may deter participation or expose the company to unnecessary risk because researchers will not know the permitted boundaries or procedures.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is a vulnerability disclosure policy important for a bug-bounty program?
Open an interactive chat with Bash
What are safe-harbor provisions in the context of vulnerability disclosure?
Open an interactive chat with Bash
What is the role of CVSS in determining reward tiers for vulnerabilities?
Open an interactive chat with Bash
What is a vulnerability disclosure policy and why is it important?
Open an interactive chat with Bash
What are safe-harbor provisions in the context of vulnerability disclosure?
Open an interactive chat with Bash
Why should a vulnerability disclosure policy be established before setting rewards or recognition tiers?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .