Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Take-Grant Model






2. Integrity






3. Economy of mechanism






4. Complete mediation






5. Security Policies


6. Threat






7. Open design






8. Management Controls






9. Implementation challenges






10. FIPS 201






11. Least privilege






12. STRIDE






13. Categories of controls






14. Common best practices significant to Sofware Security






15. Single point failure






16. Annual Rate of Occurence (ARO)






17. FIPS 197 (Advance Cryptographic standards - AES)






18. Counter measures






19. Benefits of coding standards






20. Configurations Parameters Management






21. Properties of secure software






22. Holistic Security in software






23. ISO/IEC 27006:2007






24. PCI DSS






25. Access Matrix model


26. Challenges in implementing auditing/logging






27. Safeguards






28. Least common mechanism






29. Session Management






30. Non Repudiation






31. Availability






32. Security design principles






33. ISO/IEC 27001:2005






34. OWASP Top 10






35. Phsychological acceptability






36. Popular guides developed by OWASP






37. ISO /IEC 27000:2009






38. Auditing






39. Security profile of a software






40. ISO/IEC 15408






41. Annual Loss Expectancy (ALE)






42. Software security risk management methodologies






43. Vulnerability






44. Exposure factor (EF)






45. Confidentiality






46. Security Controls






47. ISO/IEC 27005:2008






48. Error and exception management






49. After identification step is...






50. ISO/IEC 27002:2005