Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. ISO/IEC 9216






2. Software security risk management methodologies






3. Compartmentalization






4. OWASP Code Review Guide






5. Exposure factor (EF)






6. Challenges in implementing auditing/logging






7. ISO/IEC 27005:2008






8. Safeguards






9. Security Policies


10. FIPS140-2 (Security requirement for cryptographic modules)






11. Categories of controls






12. Vulnerabilities repositories






13. Security Risk Management Discipline






14. Error and exception management






15. Integrity






16. Annual Rate of Occurence (ARO)






17. Configurations Parameters Management






18. OWASP testing guide






19. Availability






20. Implementation challenges






21. OCTAVE






22. Management Controls






23. Technical Controls






24. Annual Loss Expectancy (ALE)






25. Vulnerability






26. Total Risk






27. Security Standards






28. Auditing






29. ISO/IEC 27001:2005






30. Authorization






31. FIPS 201






32. Session Management






33. Common best practices significant to Sofware Security






34. Authentication






35. ISO/IEC 15408






36. Threat






37. EALs levels






38. Least common mechanism






39. Access Matrix model


40. Residual Risk






41. Properties of secure software






42. FIPS 197 (Advance Cryptographic standards - AES)






43. DREAD






44. Single Loss Expectancy (SLE)






45. Confidentiality






46. Examples of Security Standards






47. Develop hack resilient software






48. OWASP development guide






49. Economy of mechanism






50. Operation Controls