Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Annual Rate of Occurence (ARO)






2. Management Controls






3. Software security risk management methodologies






4. Error and exception management






5. Technical Controls






6. Core Security Concept






7. Open design






8. Categories of controls






9. NIST standards related to software security






10. Security Standards






11. Authentication






12. DREAD






13. ISO /IEC 27000:2009






14. Challenges in implementing auditing/logging






15. Multifactor authentication






16. ISO/IEC 27006:2007






17. Security Policies


18. Auditing






19. Configurations Parameters Management






20. Accountability






21. Access Matrix model


22. ISO/IEC 27001:2005






23. Annual Loss Expectancy (ALE)






24. Exposure factor (EF)






25. Single Loss Expectancy (SLE)






26. Single point failure






27. Threat






28. Safeguards






29. FIPS140-2 (Security requirement for cryptographic modules)






30. Counter measures






31. Non Repudiation






32. Clipping level






33. Common best practices significant to Sofware Security






34. Economy of mechanism






35. STRIDE






36. Implementation challenges






37. Compartmentalization






38. ISO/IEC 15408






39. FIPS 197 (Advance Cryptographic standards - AES)






40. EALs levels






41. Flaw Hypothesis Method (FHM)






42. PCI DSS






43. Least common mechanism






44. Security Controls






45. OWASP Top 10






46. OWASP testing guide






47. Information Security Models






48. Authorization






49. Session Management






50. OCTAVE