Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Authentication






2. Complete mediation






3. After identification step is...






4. Core Security Concept






5. ISO/IEC 27003






6. Residual Risk






7. Security Policies


8. Multifactor authentication






9. Vulnerability






10. OWASP Top 10






11. ISO/IEC 27002:2005






12. ISO/IEC 21827:2008






13. Security Standards






14. Counter measures






15. Security Controls






16. Flaw Hypothesis Method (FHM)






17. Phsychological acceptability






18. Single point failure






19. Exposure factor (EF)






20. Non Repudiation






21. Management Controls






22. Least common mechanism






23. Take-Grant Model






24. General security concept






25. Properties of secure software






26. FIPS 197 (Advance Cryptographic standards - AES)






27. NIST standards related to software security






28. Holistic Security in software






29. Authorization






30. Security design principles






31. Annual Loss Expectancy (ALE)






32. Safeguards






33. Common best practices significant to Sofware Security






34. Popular guides developed by OWASP






35. Total Risk






36. Open design






37. Benefits of coding standards






38. OWASP testing guide






39. Challenges in implementing auditing/logging






40. EALs levels






41. ISO /IEC 27000:2009






42. ISO/IEC 27001:2005






43. Confidentiality






44. ISO/IEC 15408






45. Risk management process






46. Examples of Security Standards






47. DREAD






48. Technical Controls






49. Annual Rate of Occurence (ARO)






50. Session Management