Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Counter measures






2. Error and exception management






3. Implementation challenges






4. Information Security Models






5. Security Policies


6. FIPS 201






7. Common best practices significant to Sofware Security






8. Safeguards






9. Least privilege






10. Single Loss Expectancy (SLE)






11. OWASP Top 10






12. Economy of mechanism






13. Popular guides developed by OWASP






14. Annual Rate of Occurence (ARO)






15. Availability






16. Benefits of coding standards






17. Security design principles






18. Open design






19. Least common mechanism






20. Non Repudiation






21. OWASP testing guide






22. Configurations Parameters Management






23. Categories of controls






24. ISO/IEC 21827:2008






25. ISO/IEC 15408






26. Security Controls






27. Total Risk






28. ISO/IEC 9216






29. DREAD






30. ISO/IEC 27006:2007






31. Session Management






32. Authentication






33. Phsychological acceptability






34. Challenges in implementing auditing/logging






35. Residual Risk






36. Holistic Security in software






37. PCI DSS






38. Core Security Concept






39. Security profile of a software






40. Single point failure






41. EALs levels






42. Examples of Security Standards






43. Annual Loss Expectancy (ALE)






44. OWASP development guide






45. Authorization






46. Vulnerability






47. FIPS140-2 (Security requirement for cryptographic modules)






48. Software security risk management methodologies






49. OCTAVE






50. Auditing