Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Threat






2. Examples of Security Standards






3. Vulnerabilities repositories






4. Challenges in implementing auditing/logging






5. ISO/IEC 27003






6. Management Controls






7. Software security risk management methodologies






8. Security Risk Management Discipline






9. Least privilege






10. Counter measures






11. NIST standards related to software security






12. OWASP testing guide






13. Least common mechanism






14. Properties of secure software






15. Technical Controls






16. Develop hack resilient software






17. ISO /IEC 27000:2009






18. Access Matrix model


19. ISO/IEC 21827:2008






20. OWASP development guide






21. Safeguards






22. ISO/IEC 15408






23. Availability






24. Accountability






25. EALs levels






26. ISO/IEC 27006:2007






27. DREAD






28. Benefits of coding standards






29. Open design






30. Auditing






31. Error and exception management






32. Security profile of a software






33. Risk management process






34. OWASP Top 10






35. ISO/IEC 27001:2005






36. Information Security Models






37. ISO/IEC 27005:2008






38. FIPS140-2 (Security requirement for cryptographic modules)






39. Economy of mechanism






40. Take-Grant Model






41. General security concept






42. Popular guides developed by OWASP






43. Configurations Parameters Management






44. Security design principles






45. Annual Rate of Occurence (ARO)






46. Complete mediation






47. Session Management






48. Core Security Concept






49. OCTAVE






50. STRIDE