Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Annual Loss Expectancy (ALE)






2. Core Security Concept






3. OWASP Code Review Guide






4. Single point failure






5. FIPS140-2 (Security requirement for cryptographic modules)






6. Software security risk management methodologies






7. Common best practices significant to Sofware Security






8. Availability






9. Phsychological acceptability






10. FIPS 201






11. Configurations Parameters Management






12. Challenges in implementing auditing/logging






13. Economy of mechanism






14. OWASP Top 10






15. Counter measures






16. PCI DSS






17. Authorization






18. Threat






19. Vulnerability






20. Security Policies


21. ISO/IEC 15408






22. Compartmentalization






23. Total Risk






24. Technical Controls






25. Clipping level






26. Develop hack resilient software






27. Integrity






28. Information Security Models






29. Security design principles






30. EALs levels






31. ISO/IEC 27006:2007






32. Security profile of a software






33. Properties of secure software






34. General security concept






35. OCTAVE






36. Error and exception management






37. ISO/IEC 27003






38. Least privilege






39. Holistic Security in software






40. Least common mechanism






41. Single Loss Expectancy (SLE)






42. Operation Controls






43. DREAD






44. ISO/IEC 27001:2005






45. Security Standards






46. ISO/IEC 27005:2008






47. Safeguards






48. Access Matrix model


49. Categories of controls






50. OWASP development guide