ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your scrum team adds a security-focused user story about audit logging to the backlog. Which acceptance criterion most effectively ensures the story delivers a verifiable security control rather than a generic development task?
All transaction events must be recorded to an append-only, tamper-evident log; automated tests must fail the build if deletion or modification of existing log entries is possible.
Select and document a preferred open-source logging framework for future use.
Ensure the application generates logs that can be useful for troubleshooting according to team discretion.
Developers must insert log statements in every service method before code review begins.
Effective security acceptance criteria must be specific, measurable, and testable so the team can prove the control works before declaring the story "done." Requiring that all transaction events be written to append-only, tamper-evident storage and that an automated test fails the build if an attacker can delete or modify existing log entries provides an objective, security-relevant measure the team must meet. The other options are too vague or focus on activities (adding log statements, choosing a library, or producing "useful" logs) without defining a demonstrable security outcome, so they do not enable clear verification of the control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a tamper-evident log and its purpose?
Open an interactive chat with Bash
Why is it important for acceptance criteria to be specific, measurable, and testable?
Open an interactive chat with Bash
How do automated tests ensure tamper-evident logs are secure?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .