Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. After identification step is...






2. ISO/IEC 27005:2008






3. Technical Controls






4. ISO/IEC 21827:2008






5. OCTAVE






6. Annual Rate of Occurence (ARO)






7. ISO/IEC 27001:2005






8. OWASP testing guide






9. Single Loss Expectancy (SLE)






10. FIPS140-2 (Security requirement for cryptographic modules)






11. Authentication






12. ISO/IEC 27006:2007






13. Security Standards






14. General security concept






15. Economy of mechanism






16. Information Security Models






17. Common best practices significant to Sofware Security






18. Availability






19. Single point failure






20. Examples of Security Standards






21. Total Risk






22. ISO/IEC 27003






23. Flaw Hypothesis Method (FHM)






24. Open design






25. FIPS 197 (Advance Cryptographic standards - AES)






26. Configurations Parameters Management






27. Confidentiality






28. Security Risk Management Discipline






29. Core Security Concept






30. Access Matrix model


31. OWASP development guide






32. Take-Grant Model






33. Compartmentalization






34. FIPS 201






35. EALs levels






36. ISO/IEC 27002:2005






37. Risk management process






38. Safeguards






39. ISO/IEC 15408






40. Complete mediation






41. Authorization






42. Management Controls






43. Clipping level






44. Phsychological acceptability






45. OWASP Top 10






46. ISO /IEC 27000:2009






47. Error and exception management






48. Least privilege






49. Vulnerabilities repositories






50. NIST standards related to software security