ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your threat modeling rates the following risks (likelihood × impact scores): SQL injection 4.8, credential brute force 2.8, clear-text cardholder traffic 2.7, log tampering 1.0. Budget permits only one new control this sprint. Which control should be prioritized according to a risk-based security architecture approach?
Enforce TLS 1.3 on all payment data paths to eliminate clear-text traffic.
Digitally sign and write-protect audit logs to detect tampering.
Introduce parameterized queries and strict input validation to mitigate SQL injection.
Implement account lockout and adaptive throttling to limit credential brute-force attempts.
Risk-based prioritization selects the countermeasure that reduces the greatest quantified risk first. The highest combined likelihood and impact score is 4.8, associated with SQL injection. Implementing parameterized queries and rigorous input validation directly addresses that threat, providing the largest immediate reduction in overall risk. The other controls are valuable but mitigate lower-ranked risks and therefore would be deferred until additional resources become available.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SQL injection and why is it considered a high-risk threat?
Open an interactive chat with Bash
How do parameterized queries and strict input validation prevent SQL injection?
Open an interactive chat with Bash
What is a risk-based security architecture approach, and why is it effective?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .