ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

Your organization manages cloud resources with Terraform files stored in a Git repository that requires pull-request reviews before merge. From a security standpoint, what is the primary advantage of this Infrastructure as Code practice over making one-off changes directly in the cloud provider's web console?

  • All cloud data is automatically encrypted at rest without needing additional configuration steps.

  • It eliminates the need for formal change-management approval, allowing faster deployments without peer review.

  • The approach inherently protects resources from denial-of-service attacks by throttling API requests.

  • Each infrastructure change is tracked in version control, creating an auditable history and enabling safe rollback to trusted states.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot