Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. ISO/IEC 27006:2007






2. Software security risk management methodologies






3. Popular guides developed by OWASP






4. Confidentiality






5. FIPS 197 (Advance Cryptographic standards - AES)






6. ISO /IEC 27000:2009






7. ISO/IEC 9216






8. STRIDE






9. Annual Loss Expectancy (ALE)






10. Benefits of coding standards






11. Total Risk






12. Properties of secure software






13. Challenges in implementing auditing/logging






14. OWASP Top 10






15. Information Security Models






16. General security concept






17. FIPS140-2 (Security requirement for cryptographic modules)






18. ISO/IEC 27005:2008






19. Develop hack resilient software






20. NIST standards related to software security






21. Session Management






22. OCTAVE






23. Risk management process






24. Vulnerability






25. ISO/IEC 21827:2008






26. Configurations Parameters Management






27. Economy of mechanism






28. Examples of Security Standards






29. Safeguards






30. Error and exception management






31. ISO/IEC 27003






32. Annual Rate of Occurence (ARO)






33. Take-Grant Model






34. Threat






35. Auditing






36. Multifactor authentication






37. Technical Controls






38. After identification step is...






39. Phsychological acceptability






40. Security Controls






41. Implementation challenges






42. Categories of controls






43. Security design principles






44. ISO/IEC 27002:2005






45. Counter measures






46. Single Loss Expectancy (SLE)






47. ISO/IEC 15408






48. Open design






49. Authentication






50. Core Security Concept