Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Threat






2. General security concept






3. OWASP Top 10






4. Software security risk management methodologies






5. After identification step is...






6. Properties of secure software






7. ISO/IEC 27002:2005






8. Categories of controls






9. Develop hack resilient software






10. Authorization






11. Safeguards






12. Configurations Parameters Management






13. ISO/IEC 15408






14. Error and exception management






15. Examples of Security Standards






16. Operation Controls






17. Security Controls






18. Annual Loss Expectancy (ALE)






19. Availability






20. Auditing






21. Risk management process






22. Take-Grant Model






23. Complete mediation






24. Security design principles






25. Accountability






26. Implementation challenges






27. ISO/IEC 27005:2008






28. ISO/IEC 27003






29. Open design






30. OWASP testing guide






31. FIPS 197 (Advance Cryptographic standards - AES)






32. Counter measures






33. Access Matrix model


34. Benefits of coding standards






35. PCI DSS






36. Security Policies


37. Single Loss Expectancy (SLE)






38. Multifactor authentication






39. Security Standards






40. Phsychological acceptability






41. Annual Rate of Occurence (ARO)






42. Compartmentalization






43. Information Security Models






44. DREAD






45. OCTAVE






46. Confidentiality






47. Clipping level






48. Challenges in implementing auditing/logging






49. STRIDE






50. ISO/IEC 27006:2007