Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Session Management






2. Counter measures






3. Authentication






4. ISO/IEC 9216






5. FIPS140-2 (Security requirement for cryptographic modules)






6. Confidentiality






7. Annual Rate of Occurence (ARO)






8. ISO/IEC 27003






9. FIPS 201






10. Management Controls






11. Multifactor authentication






12. Accountability






13. EALs levels






14. Configurations Parameters Management






15. ISO/IEC 27006:2007






16. Challenges in implementing auditing/logging






17. Auditing






18. Availability






19. After identification step is...






20. Holistic Security in software






21. Threat






22. Integrity






23. Popular guides developed by OWASP






24. Exposure factor (EF)






25. Security Standards






26. General security concept






27. Vulnerabilities repositories






28. OWASP testing guide






29. Clipping level






30. Non Repudiation






31. Benefits of coding standards






32. Risk management process






33. Software security risk management methodologies






34. Economy of mechanism






35. OWASP Code Review Guide






36. Security design principles






37. Categories of controls






38. Security Risk Management Discipline






39. Properties of secure software






40. Examples of Security Standards






41. Security profile of a software






42. Vulnerability






43. OCTAVE






44. Single Loss Expectancy (SLE)






45. Operation Controls






46. Residual Risk






47. PCI DSS






48. Complete mediation






49. Phsychological acceptability






50. Least privilege