Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Take-Grant Model






2. Clipping level






3. Configurations Parameters Management






4. Non Repudiation






5. Security Risk Management Discipline






6. ISO/IEC 27005:2008






7. Holistic Security in software






8. ISO /IEC 27000:2009






9. Categories of controls






10. General security concept






11. Authentication






12. Security Controls






13. Compartmentalization






14. Security profile of a software






15. ISO/IEC 27003






16. Phsychological acceptability






17. Risk management process






18. After identification step is...






19. Benefits of coding standards






20. FIPS140-2 (Security requirement for cryptographic modules)






21. Operation Controls






22. Implementation challenges






23. EALs levels






24. Single Loss Expectancy (SLE)






25. Integrity






26. Security design principles






27. DREAD






28. Least common mechanism






29. Flaw Hypothesis Method (FHM)






30. STRIDE






31. Technical Controls






32. Challenges in implementing auditing/logging






33. Least privilege






34. Information Security Models






35. Examples of Security Standards






36. FIPS 197 (Advance Cryptographic standards - AES)






37. Economy of mechanism






38. Safeguards






39. ISO/IEC 9216






40. OWASP Code Review Guide






41. Software security risk management methodologies






42. Annual Rate of Occurence (ARO)






43. Common best practices significant to Sofware Security






44. ISO/IEC 21827:2008






45. Confidentiality






46. Open design






47. Counter measures






48. Vulnerabilities repositories






49. ISO/IEC 27001:2005






50. FIPS 201