/* */

Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Software security risk management methodologies






2. Complete mediation






3. OWASP testing guide






4. Holistic Security in software






5. Safeguards






6. Security Standards






7. Technical Controls






8. Common best practices significant to Sofware Security






9. Session Management






10. Popular guides developed by OWASP






11. Operation Controls






12. ISO/IEC 27006:2007






13. Develop hack resilient software






14. Non Repudiation






15. STRIDE






16. Auditing






17. Categories of controls






18. Authentication






19. Least privilege






20. DREAD






21. FIPS140-2 (Security requirement for cryptographic modules)






22. Information Security Models






23. After identification step is...






24. Challenges in implementing auditing/logging






25. Authorization






26. Annual Rate of Occurence (ARO)






27. Annual Loss Expectancy (ALE)






28. General security concept






29. FIPS 201






30. ISO /IEC 27000:2009






31. Vulnerabilities repositories






32. Error and exception management






33. ISO/IEC 15408






34. NIST standards related to software security






35. Residual Risk






36. Take-Grant Model






37. Implementation challenges






38. Phsychological acceptability






39. Management Controls






40. Risk management process






41. Properties of secure software






42. Integrity






43. Open design






44. Single Loss Expectancy (SLE)






45. Benefits of coding standards






46. Single point failure






47. Availability






48. EALs levels






49. ISO/IEC 27002:2005






50. Least common mechanism






//