Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Annual Rate of Occurence (ARO)






2. Security Standards






3. Vulnerabilities repositories






4. Error and exception management






5. ISO/IEC 27003






6. Safeguards






7. Open design






8. PCI DSS






9. Access Matrix model


10. Security Risk Management Discipline






11. Counter measures






12. FIPS140-2 (Security requirement for cryptographic modules)






13. Authorization






14. Security design principles






15. ISO/IEC 27006:2007






16. Multifactor authentication






17. Accountability






18. Least common mechanism






19. STRIDE






20. Clipping level






21. OWASP development guide






22. Flaw Hypothesis Method (FHM)






23. Auditing






24. Benefits of coding standards






25. Authentication






26. General security concept






27. Economy of mechanism






28. EALs levels






29. Threat






30. Operation Controls






31. Take-Grant Model






32. Properties of secure software






33. OWASP Code Review Guide






34. Complete mediation






35. Compartmentalization






36. Develop hack resilient software






37. OWASP Top 10






38. Configurations Parameters Management






39. Challenges in implementing auditing/logging






40. Implementation challenges






41. Single point failure






42. ISO/IEC 27005:2008






43. FIPS 197 (Advance Cryptographic standards - AES)






44. Examples of Security Standards






45. Confidentiality






46. Residual Risk






47. Security Policies


48. Core Security Concept






49. ISO/IEC 15408






50. ISO/IEC 27002:2005