Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Categories of controls






2. OCTAVE






3. ISO/IEC 21827:2008






4. Risk management process






5. Non Repudiation






6. FIPS 197 (Advance Cryptographic standards - AES)






7. OWASP development guide






8. Security profile of a software






9. Counter measures






10. OWASP Top 10






11. Security Controls






12. Safeguards






13. STRIDE






14. Core Security Concept






15. Multifactor authentication






16. Availability






17. Software security risk management methodologies






18. EALs levels






19. Operation Controls






20. PCI DSS






21. Exposure factor (EF)






22. Economy of mechanism






23. Common best practices significant to Sofware Security






24. NIST standards related to software security






25. Phsychological acceptability






26. Annual Rate of Occurence (ARO)






27. Error and exception management






28. Flaw Hypothesis Method (FHM)






29. Configurations Parameters Management






30. Properties of secure software






31. Least privilege






32. Integrity






33. Authorization






34. OWASP Code Review Guide






35. Develop hack resilient software






36. Information Security Models






37. Auditing






38. Total Risk






39. Management Controls






40. Security Policies


41. ISO/IEC 27003






42. Complete mediation






43. FIPS 201






44. Session Management






45. Single Loss Expectancy (SLE)






46. ISO/IEC 9216






47. Least common mechanism






48. ISO/IEC 27002:2005






49. Vulnerabilities repositories






50. Confidentiality