Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. OCTAVE






2. Authorization






3. FIPS 201






4. ISO/IEC 27003






5. Technical Controls






6. Economy of mechanism






7. Safeguards






8. Properties of secure software






9. After identification step is...






10. Security Policies


11. Access Matrix model


12. FIPS140-2 (Security requirement for cryptographic modules)






13. Residual Risk






14. Session Management






15. Authentication






16. Software security risk management methodologies






17. Security design principles






18. Error and exception management






19. Compartmentalization






20. Single Loss Expectancy (SLE)






21. FIPS 197 (Advance Cryptographic standards - AES)






22. OWASP Code Review Guide






23. Availability






24. Develop hack resilient software






25. Holistic Security in software






26. Security Controls






27. ISO/IEC 15408






28. Vulnerability






29. Exposure factor (EF)






30. Common best practices significant to Sofware Security






31. STRIDE






32. Challenges in implementing auditing/logging






33. Least privilege






34. ISO/IEC 21827:2008






35. Open design






36. Operation Controls






37. Security Risk Management Discipline






38. Total Risk






39. PCI DSS






40. Security profile of a software






41. Complete mediation






42. Auditing






43. Clipping level






44. Annual Loss Expectancy (ALE)






45. ISO/IEC 27005:2008






46. ISO/IEC 27002:2005






47. OWASP development guide






48. OWASP testing guide






49. Benefits of coding standards






50. Vulnerabilities repositories