Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. FIPS 197 (Advance Cryptographic standards - AES)






2. Security Policies


3. Integrity






4. Implementation challenges






5. ISO /IEC 27000:2009






6. Core Security Concept






7. Authorization






8. Clipping level






9. Multifactor authentication






10. General security concept






11. After identification step is...






12. Flaw Hypothesis Method (FHM)






13. Exposure factor (EF)






14. Vulnerabilities repositories






15. Auditing






16. Develop hack resilient software






17. Operation Controls






18. Benefits of coding standards






19. ISO/IEC 27006:2007






20. Risk management process






21. Security design principles






22. Software security risk management methodologies






23. ISO/IEC 27002:2005






24. ISO/IEC 27001:2005






25. Session Management






26. Security Risk Management Discipline






27. OCTAVE






28. OWASP testing guide






29. ISO/IEC 9216






30. Phsychological acceptability






31. Safeguards






32. Non Repudiation






33. FIPS140-2 (Security requirement for cryptographic modules)






34. Compartmentalization






35. Least privilege






36. Annual Rate of Occurence (ARO)






37. Error and exception management






38. OWASP Code Review Guide






39. PCI DSS






40. Examples of Security Standards






41. Open design






42. Annual Loss Expectancy (ALE)






43. Authentication






44. Information Security Models






45. Challenges in implementing auditing/logging






46. Take-Grant Model






47. Security profile of a software






48. ISO/IEC 27003






49. Single Loss Expectancy (SLE)






50. Vulnerability