Cyber Secure Software Developer Exam Prep
Free practice questions

Free CSSD Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

These 10 free CSSD questions are organized by exam domain, so you can see how each part of the Cyber Secure Software Developer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Understand the Fundamentals of Secure Software Development 15% of exam

Question 1

An authenticated user visits an unrelated website. A hidden form there submits a profile-change request to the user's account on another service, and the browser automatically includes that service's session cookie. The change succeeds without the user's approval. Investigation finds no injected script on the account service and no copied cookie. Which attack best fits this evidence?

Show answer & explanation

Correct answer: C - Cross-site request forgery using the browser's existing authenticated session.

Question 2

An engineer must apply a reviewed schema migration to one production database during a 30-minute maintenance window. The change needs schema-alteration rights, not user administration or access to other databases. Which access arrangement fits the job without leaving unnecessary privileges behind?

Show answer & explanation

Correct answer: B - Grant the engineer database-scoped schema-alteration privileges with automatic expiry after the approved window.

Domain 2: Explain the Secure Software Development Lifecycle 22% of exam

Question 3

The test lead makes a specific request: "When our regression suite triggers this finding, I need the internal method and data flow responsible." Tests run against a deployed service, and the team can install an agent in that test runtime. Which technique supplies the requested execution evidence?

Show answer & explanation

Correct answer: D - Interactive application security testing inside the running service.

Question 4

"The AI wrote the handler and its tests; everything passes, so we can merge." The approved coding assistant produced a password-reset handler whose security requirement is that each token may succeed only once. Every generated test uses a fresh token, and static analysis is clean. Which independent review step would add the most relevant security evidence?

Show answer & explanation

Correct answer: B - Independently test a second use of the same token and require rejection.

Domain 3: Develop Secure Code 33% of exam

Question 5

In a billing API, employees may read any invoice belonging to their own company, but never another company's. A signed-in employee replaces an invoice UUID in GET /invoices/{id} with a UUID learned from another company. The API returns that invoice. Session validation succeeds, and the query uses bound parameters. Which change closes the demonstrated gap?

Show answer & explanation

Correct answer: D - Check that the invoice belongs to the tenant identified by the validated session.

Question 6

A search endpoint binds its search term, but constructs its SQL statement as follows: sql = "SELECT id, name FROM items WHERE name = ? ORDER BY " + request.sort Only name and created_at are permitted sort columns, and both must remain available. The driver cannot bind column identifiers. Select the repair that preserves sorting without accepting SQL structure from the request.

Show answer & explanation

Correct answer: A - Map each permitted sort choice to a fixed server-side column name.

Question 7

A service encrypts records with AES-256-GCM using one key shared by several workers. Each worker derives its 96-bit nonce from a local counter that starts at zero whenever the worker starts. Encryption and decryption tests pass on each worker. What must change before concurrent operation is considered secure?

Show answer & explanation

Correct answer: C - Ensure nonce uniqueness across all workers and restarts for each encryption key.

Domain 4: Defending Against Cyberattacks 15% of exam

Question 8

Monitoring confirms that one application server is receiving attacker commands over HTTPS and sending customer files to changing external destinations. The incident responder can isolate that server through endpoint controls without interrupting the other servers. Centralized logs are already preserved. What should the responder do first to contain the activity?

Show answer & explanation

Correct answer: A - Isolate the affected server while keeping it powered on for evidence collection.

Domain 5: Engage in Governance, Risk Management, and Compliance 15% of exam

Question 9

A vendor releases version 4.2 of a document-processing service. A new advisory affects a parser that may be included through a transitive dependency. Procurement holds a software bill of materials (SBOM) for version 4.1, while production runs a 4.2 container identified by its digest. Which record would most directly establish whether the affected parser version is included?

Show answer & explanation

Correct answer: B - A build-generated SBOM tied to the deployed digest, including component versions and dependency relationships.

Question 10

A customer asks a software supplier, "Show us that your access controls operated effectively from January through June." The supplier submits a SOC 2 Type 1 report as of June 30. The customer still lacks the requested period-specific evidence. Which document should the supplier provide?

Show answer & explanation

Correct answer: C - A SOC 2 Type 2 report covering those controls throughout the January-June period.

That's 10 of 1,030

The full bank has 1,020 more CSSD questions with explanations.

Continue in the free practice test →

View plans