Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Auditing






2. OWASP Code Review Guide






3. Common best practices significant to Sofware Security






4. Security Policies


5. Economy of mechanism






6. Vulnerability






7. FIPS 197 (Advance Cryptographic standards - AES)






8. Authentication






9. General security concept






10. Least common mechanism






11. Error and exception management






12. ISO/IEC 27005:2008






13. Exposure factor (EF)






14. Availability






15. Single Loss Expectancy (SLE)






16. Operation Controls






17. Popular guides developed by OWASP






18. Integrity






19. Open design






20. After identification step is...






21. Confidentiality






22. Complete mediation






23. NIST standards related to software security






24. ISO/IEC 27001:2005






25. Non Repudiation






26. Compartmentalization






27. Flaw Hypothesis Method (FHM)






28. Access Matrix model


29. Accountability






30. ISO/IEC 27006:2007






31. Security profile of a software






32. Counter measures






33. Benefits of coding standards






34. Security design principles






35. Safeguards






36. Single point failure






37. Annual Loss Expectancy (ALE)






38. Implementation challenges






39. Risk management process






40. ISO/IEC 9216






41. ISO/IEC 27002:2005






42. Least privilege






43. Take-Grant Model






44. Configurations Parameters Management






45. Holistic Security in software






46. ISO/IEC 15408






47. Security Controls






48. OCTAVE






49. Technical Controls






50. Authorization