Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. OCTAVE






2. Accountability






3. Safeguards






4. NIST standards related to software security






5. Software security risk management methodologies






6. Annual Rate of Occurence (ARO)






7. Benefits of coding standards






8. Security Policies


9. Vulnerability






10. ISO/IEC 9216






11. Security design principles






12. Integrity






13. Total Risk






14. Core Security Concept






15. ISO/IEC 27003






16. Information Security Models






17. Non Repudiation






18. ISO/IEC 15408






19. Management Controls






20. ISO/IEC 27005:2008






21. ISO/IEC 27001:2005






22. OWASP development guide






23. Operation Controls






24. Flaw Hypothesis Method (FHM)






25. FIPS140-2 (Security requirement for cryptographic modules)






26. Confidentiality






27. Least common mechanism






28. Examples of Security Standards






29. EALs levels






30. General security concept






31. Counter measures






32. Authorization






33. OWASP Code Review Guide






34. Properties of secure software






35. Risk management process






36. Vulnerabilities repositories






37. Implementation challenges






38. Exposure factor (EF)






39. OWASP testing guide






40. Challenges in implementing auditing/logging






41. Economy of mechanism






42. Take-Grant Model






43. PCI DSS






44. Security profile of a software






45. Security Standards






46. ISO/IEC 21827:2008






47. Authentication






48. Compartmentalization






49. Single Loss Expectancy (SLE)






50. ISO/IEC 27006:2007