Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. NIST standards related to software security






2. OCTAVE






3. OWASP Code Review Guide






4. Safeguards






5. Annual Rate of Occurence (ARO)






6. Operation Controls






7. FIPS 201






8. Accountability






9. DREAD






10. Security Controls






11. Risk management process






12. OWASP testing guide






13. Access Matrix model


14. Core Security Concept






15. Economy of mechanism






16. ISO/IEC 27006:2007






17. Security Policies


18. Least common mechanism






19. Challenges in implementing auditing/logging






20. Security Risk Management Discipline






21. Security Standards






22. Authentication






23. Configurations Parameters Management






24. Non Repudiation






25. Least privilege






26. ISO/IEC 27001:2005






27. Information Security Models






28. STRIDE






29. Clipping level






30. Single point failure






31. Categories of controls






32. Multifactor authentication






33. ISO/IEC 21827:2008






34. Flaw Hypothesis Method (FHM)






35. ISO /IEC 27000:2009






36. Session Management






37. Counter measures






38. After identification step is...






39. Availability






40. ISO/IEC 15408






41. Complete mediation






42. Single Loss Expectancy (SLE)






43. Auditing






44. Residual Risk






45. FIPS 197 (Advance Cryptographic standards - AES)






46. Threat






47. ISO/IEC 27005:2008






48. ISO/IEC 9216






49. FIPS140-2 (Security requirement for cryptographic modules)






50. ISO/IEC 27002:2005