8.0 Software Development Security CISSP Practice Quiz

80 exam-style questions covering 10% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A national bank's mobile app team is integrating security into its monthly release train. The security team must make a software development security decision involving security in the Software Development Life Cycle. What is the best recommendation?
  • A. Define security requirements during planning and requirements phases before architecture and implementation decisions are fixed
  • B. Strip security review from high-impact pipelines to improve delivery velocity
  • C. Treat application retirement as out of scope for the SDLC
  • D. Define security requirements only after the application is in production

Security requirements are most effective when they guide design choices early in the SDLC. This is the correct answer.

A regional credit union is rolling out application threat modeling for new digital products. A proposed development process creates risk around security in the Software Development Life Cycle. Which change best addresses the concern?
  • A. Require remediation tracking and risk acceptance for unresolved findings before production release
  • B. Treat decommissioning of an application as outside engineering's responsibility
  • C. Postpone security requirements until after the first prod release
  • D. Run SAST on every PR and call the SDLC security 'covered'

Release decisions need evidence, ownership, and explicit treatment of residual risk. This is the correct answer.

A health-tech startup is hardening its patient-portal pipeline ahead of a HITRUST audit. An application security review identifies a weakness in security in the Software Development Life Cycle. Which action should be prioritized?
  • A. Allow individual developers to accept residual business risk on their own
  • B. Use threat modeling during design to identify assets, trust boundaries, misuse cases, and likely attack paths
  • C. Disable security gates on critical-system deploys to keep release cadence fast
  • D. Skip decommissioning planning as a software lifecycle activity

Threat modeling helps turn design risks into actionable requirements and controls. This is the correct answer.

A consumer fintech is rebuilding its mobile authentication module after a fraud spike. Executives need a risk-based explanation for security in the Software Development Life Cycle. Which response best aligns with secure software practice?
  • A. Skip security checks on high-impact services so delivery teams can move faster
  • B. Include security acceptance criteria in user stories or requirements so teams know how security will be validated
  • C. Drop the retirement phase from the SDLC stages
  • D. Skip security requirements during design and add them post-launch

Acceptance criteria make security testable and visible to product and engineering teams. This is the correct answer.

A regional retailer is reviewing the security of its e-commerce checkout microservice. A software assurance exercise must address security in the Software Development Life Cycle. What should the security professional recommend?
  • A. Skip secure-decommissioning steps in the formal lifecycle
  • B. Use security champions to extend application security guidance into development teams
  • C. Define security requirements only after the system is operational
  • D. Treat code scanners as a one-stop shop for application security

Champions help sustain secure practices within teams that make daily design and implementation choices. This is the correct answer.

A federal contractor is aligning its software supply chain with revised SSDF guidance. The CISO asks for CISSP-level guidance on security in the Software Development Life Cycle. Which approach is most appropriate?
  • A. Treat SAST scanning as the sole security activity in the SDLC
  • B. Permit engineers to close out residual risks without product-owner concurrence
  • C. Include secure design reviews before approving architecture for sensitive or high-impact applications
  • D. Remove SDL gates from high-risk apps to avoid slowing the release train

Architecture review can identify design-level flaws that code scanning alone will not find. This is the correct answer.

A pediatric hospital is securing a clinical data exchange written by an external vendor. The security team must make a software development security decision involving security in the Software Development Life Cycle. What is the best recommendation?
  • A. Let dev teams self-accept residual business risk with no product or risk-owner sign-off
  • B. Drop secure-design reviews on critical applications to reduce time-to-market
  • C. Perform privacy and data protection reviews when software collects, processes, or shares personal information
  • D. Treat application end-of-life as a separate concern from the SDLC

Privacy risk should be addressed in the same lifecycle that designs the data flows. This is the correct answer.

A SaaS analytics firm is overhauling its CI/CD security after a leaked-secret incident. A software assurance exercise must address security in the Software Development Life Cycle. What should the security professional recommend?
  • A. Defer security requirements gathering until after the launch is complete
  • B. Use code scanning as the entire application security program
  • C. Skip risk-owner approval on accepted residual risk for the application
  • D. Integrate static, dynamic, and interactive testing into build and release activities according to risk

Security testing should be embedded into lifecycle gates rather than treated as a final one-time activity. This is the correct answer.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/isc2-cissp/software-development-security/

<a href="https://quizbuffet.com/isc2-cissp/software-development-security/">CISSP (ISC2) Software Development Security practice quiz on QuizBuffet</a>

Other CISSP Domains

← Back to CISSP practice test overview

Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.