8.0 Software Development Security CISSP Practice Quiz
80 exam-style questions covering 10% of the CISSP exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the Certified Information Systems Security Professional practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
A national bank's mobile app team is integrating security into its monthly release train. The security team must make a software development security decision involving security in the Software Development Life Cycle. What is the best recommendation?
- A. Define security requirements during planning and requirements phases before architecture and implementation decisions are fixed
- B. Strip security review from high-impact pipelines to improve delivery velocity
- C. Treat application retirement as out of scope for the SDLC
- D. Define security requirements only after the application is in production
Security requirements are most effective when they guide design choices early in the SDLC. This is the correct answer.
A regional credit union is rolling out application threat modeling for new digital products. A proposed development process creates risk around security in the Software Development Life Cycle. Which change best addresses the concern?
- A. Require remediation tracking and risk acceptance for unresolved findings before production release
- B. Treat decommissioning of an application as outside engineering's responsibility
- C. Postpone security requirements until after the first prod release
- D. Run SAST on every PR and call the SDLC security 'covered'
Release decisions need evidence, ownership, and explicit treatment of residual risk. This is the correct answer.
A health-tech startup is hardening its patient-portal pipeline ahead of a HITRUST audit. An application security review identifies a weakness in security in the Software Development Life Cycle. Which action should be prioritized?
- A. Allow individual developers to accept residual business risk on their own
- B. Use threat modeling during design to identify assets, trust boundaries, misuse cases, and likely attack paths
- C. Disable security gates on critical-system deploys to keep release cadence fast
- D. Skip decommissioning planning as a software lifecycle activity
Threat modeling helps turn design risks into actionable requirements and controls. This is the correct answer.
A consumer fintech is rebuilding its mobile authentication module after a fraud spike. Executives need a risk-based explanation for security in the Software Development Life Cycle. Which response best aligns with secure software practice?
- A. Skip security checks on high-impact services so delivery teams can move faster
- B. Include security acceptance criteria in user stories or requirements so teams know how security will be validated
- C. Drop the retirement phase from the SDLC stages
- D. Skip security requirements during design and add them post-launch
Acceptance criteria make security testable and visible to product and engineering teams. This is the correct answer.
A regional retailer is reviewing the security of its e-commerce checkout microservice. A software assurance exercise must address security in the Software Development Life Cycle. What should the security professional recommend?
- A. Skip secure-decommissioning steps in the formal lifecycle
- B. Use security champions to extend application security guidance into development teams
- C. Define security requirements only after the system is operational
- D. Treat code scanners as a one-stop shop for application security
Champions help sustain secure practices within teams that make daily design and implementation choices. This is the correct answer.
A federal contractor is aligning its software supply chain with revised SSDF guidance. The CISO asks for CISSP-level guidance on security in the Software Development Life Cycle. Which approach is most appropriate?
- A. Treat SAST scanning as the sole security activity in the SDLC
- B. Permit engineers to close out residual risks without product-owner concurrence
- C. Include secure design reviews before approving architecture for sensitive or high-impact applications
- D. Remove SDL gates from high-risk apps to avoid slowing the release train
Architecture review can identify design-level flaws that code scanning alone will not find. This is the correct answer.
A pediatric hospital is securing a clinical data exchange written by an external vendor. The security team must make a software development security decision involving security in the Software Development Life Cycle. What is the best recommendation?
- A. Let dev teams self-accept residual business risk with no product or risk-owner sign-off
- B. Drop secure-design reviews on critical applications to reduce time-to-market
- C. Perform privacy and data protection reviews when software collects, processes, or shares personal information
- D. Treat application end-of-life as a separate concern from the SDLC
Privacy risk should be addressed in the same lifecycle that designs the data flows. This is the correct answer.
A SaaS analytics firm is overhauling its CI/CD security after a leaked-secret incident. A software assurance exercise must address security in the Software Development Life Cycle. What should the security professional recommend?
- A. Defer security requirements gathering until after the launch is complete
- B. Use code scanning as the entire application security program
- C. Skip risk-owner approval on accepted residual risk for the application
- D. Integrate static, dynamic, and interactive testing into build and release activities according to risk
Security testing should be embedded into lifecycle gates rather than treated as a final one-time activity. This is the correct answer.
Key Terms in This Domain
- SDLC: Software Development Life Cycle: phases from requirements to disposal
- Risk Mitigation: Apply controls to reduce likelihood or impact
- NIST Risk Management Framework: NIST SP 800-37 lifecycle for managing information system risk
- Data Lifecycle: Create, store, use, share, archive, destroy
- SOC 2: Service Organization Controls report on security/availability/confidentiality
- Secure Coding: Practices that prevent common vulnerabilities (input validation, output encoding)
- CIA Triad: Confidentiality, Integrity, Availability: core information security objectives
- 5 Pillars of Information Security: Confidentiality, integrity, availability, authenticity, and nonrepudiation
- Due Diligence: Ongoing effort to investigate, assess, and verify controls and risks
- Risk: Likelihood of a threat exploiting a vulnerability and resulting impact
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/isc2-cissp/software-development-security/
<a href="https://quizbuffet.com/isc2-cissp/software-development-security/">CISSP (ISC2) Software Development Security practice quiz on QuizBuffet</a>
Other CISSP Domains
- 1.0 Security and Risk Management
- 2.0 Asset Security
- 3.0 Security Architecture and Engineering
- 4.0 Communication and Network Security
- 5.0 Identity and Access Management (IAM)
- 6.0 Security Assessment and Testing
- 7.0 Security Operations
← Back to CISSP practice test overview
Questions are written against the published CISSP objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.