ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization plans to embed a third-party image-processing SDK in a mobile app. To reduce security risk, the contract must oblige the vendor to produce verifiable security-testing evidence and drive prompt remediation. Which contractual clause most directly meets this need?
Mandate that the vendor provide a software bill of materials (SBOM) for all open-source components used.
Grant the customer read-only access to the vendor's internal bug-tracking system to observe security tickets.
Require the vendor to submit an annual self-signed letter asserting compliance with ISO/IEC 27001 controls.
Require the vendor to deliver an independent penetration-test report every year and remediate all high-severity findings within 30 days.
A clause that demands an independent penetration-test report on a regular schedule and sets firm timelines for fixing serious findings gives the customer concrete, reviewable evidence that security testing actually occurred and ensures that uncovered vulnerabilities will be addressed quickly. The other clauses either rely only on self-attestation, provide visibility without guaranteeing testing, or supply useful component inventory information but no proof that the software has been security-tested or that issues will be remediated.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an independent penetration-test report?
Open an interactive chat with Bash
What is a software bill of materials (SBOM)?
Open an interactive chat with Bash
How do ISO/IEC 27001 controls relate to security testing?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .