Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 20 minutes. 2 minutes extra for reading the instructions.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. FIPS140-2 (Security requirement for cryptographic modules)






2. Threat






3. Single Loss Expectancy (SLE)






4. Counter measures






5. ISO/IEC 9216






6. Benefits of coding standards






7. OWASP Top 10






8. Confidentiality






9. Configurations Parameters Management






10. Availability






11. Annual Loss Expectancy (ALE)






12. Accountability






13. Multifactor authentication






14. Technical Controls






15. Compartmentalization






16. Authentication






17. Least privilege






18. Flaw Hypothesis Method (FHM)






19. Security profile of a software






20. ISO/IEC 27002:2005






21. Access Matrix model


22. Safeguards






23. ISO/IEC 27001:2005






24. OWASP Code Review Guide






25. ISO/IEC 27006:2007






26. Annual Rate of Occurence (ARO)






27. ISO /IEC 27000:2009






28. ISO/IEC 27005:2008






29. Implementation challenges






30. Economy of mechanism






31. Integrity






32. ISO/IEC 15408






33. Risk management process






34. Auditing






35. Holistic Security in software






36. Phsychological acceptability






37. Software security risk management methodologies






38. NIST standards related to software security






39. ISO/IEC 27003






40. Categories of controls






41. Develop hack resilient software






42. Challenges in implementing auditing/logging






43. Information Security Models






44. OCTAVE






45. Vulnerability






46. Vulnerabilities repositories






47. PCI DSS






48. Popular guides developed by OWASP






49. Authorization






50. Operation Controls