CSSLP Certification Sample Questions

ISC2 CSSLP Sample Questions:

01. Which of the following is a security standard associated with the collection, processing, and storing of credit card data?
a) Gramm-Leach-Bliley
02. A security policy that is associated with securing PII is an example of what type of computer security policy?
a) System-specific policy
b) Program policy
c) Organizational policy
d) Issue-specific policy
03. Backups are an example of what type of control?
a) Preventive
b) Detective
c) Corrective
d) Operational
04. To match the level of protection desired for data, which of the following elements is used?
a) Data classification
b) Impact analysis
c) Data usage
d) Security rules
05. An activity designed to clarify requirements through the modeling of expected behaviors of a system is called what?
a) Functional requirement decomposition
b) Requirement traceability matrix
c) Threat modeling
d) Use-case modeling
06. The attack surface of your project seems to grow faster than it should. Which of the following is probably not a fruitful place to look?
a) Number of modules/routines in the project
b) Privilege level of the credentials used to run the application
c) Network address space from which the program is addressable
d) Privilege level of users using the application
07. Input strings similar to %2e%2e%2f are indicative of what type of attack?
a) Command injection
b) SQL injection
c) Directory traversal
d) Buffer overflow
08. Designing a system so all parties can easily understand design objectives and maintaining a simple design embrace the principle of?
a) Single point of failure
b) Least common mechanism
c) Fail safe
d) Open design
09. What was described in the chapter as being essential in order to implement discretionary access control?
a) Object owner–defined security access
b) Certificates
c) Labels
d) Security classifications
10. Functional testing is used to determine which of the following characteristics?
a) Reliability, bugs, performance, and scalability
b) Resiliency, logic, security, and testability
c) Resiliency, bugs, requirements, and scalability
d) Reliability, logic, performance, and scalability


Question: 01
Answer: b
Question: 02
Answer: d
Question: 03
Answer: c
Question: 04
Answer: a
Question: 05
Answer: d
Question: 06
Answer: a
Question: 07
Answer: c
Question: 08
Answer: d
Question: 09
Answer: a
Question: 10
Answer: d

