Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. ISO/IEC 27006:2007






2. Open design






3. FIPS 197 (Advance Cryptographic standards - AES)






4. Security Risk Management Discipline






5. DREAD






6. ISO /IEC 27000:2009






7. Flaw Hypothesis Method (FHM)






8. ISO/IEC 27002:2005






9. Examples of Security Standards






10. Compartmentalization






11. Authorization






12. Exposure factor (EF)






13. Common best practices significant to Sofware Security






14. Annual Rate of Occurence (ARO)






15. Security design principles






16. Non Repudiation






17. ISO/IEC 21827:2008






18. OWASP Code Review Guide






19. Safeguards






20. Security profile of a software






21. Least common mechanism






22. Security Policies


23. Session Management






24. Counter measures






25. Clipping level






26. Phsychological acceptability






27. Technical Controls






28. Operation Controls






29. Complete mediation






30. Threat






31. Residual Risk






32. Properties of secure software






33. Challenges in implementing auditing/logging






34. STRIDE






35. Total Risk






36. Configurations Parameters Management






37. Core Security Concept






38. General security concept






39. Take-Grant Model






40. OWASP Top 10






41. ISO/IEC 27005:2008






42. Risk management process






43. FIPS140-2 (Security requirement for cryptographic modules)






44. After identification step is...






45. Economy of mechanism






46. ISO/IEC 9216






47. ISO/IEC 27003






48. Categories of controls






49. ISO/IEC 15408






50. Security Standards






//