Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Security Policies


2. ISO/IEC 27006:2007






3. After identification step is...






4. Implementation challenges






5. Safeguards






6. Flaw Hypothesis Method (FHM)






7. Develop hack resilient software






8. Vulnerability






9. OWASP Code Review Guide






10. Common best practices significant to Sofware Security






11. Categories of controls






12. Session Management






13. Properties of secure software






14. Security profile of a software






15. Open design






16. Security design principles






17. Annual Rate of Occurence (ARO)






18. OWASP Top 10






19. Economy of mechanism






20. Authentication






21. Information Security Models






22. PCI DSS






23. Take-Grant Model






24. Least privilege






25. ISO/IEC 27002:2005






26. Security Standards






27. Non Repudiation






28. Exposure factor (EF)






29. ISO /IEC 27000:2009






30. ISO/IEC 21827:2008






31. FIPS 201






32. DREAD






33. Clipping level






34. FIPS140-2 (Security requirement for cryptographic modules)






35. Popular guides developed by OWASP






36. Multifactor authentication






37. Access Matrix model


38. General security concept






39. Auditing






40. OCTAVE






41. Challenges in implementing auditing/logging






42. Residual Risk






43. ISO/IEC 9216






44. Phsychological acceptability






45. Examples of Security Standards






46. Total Risk






47. Integrity






48. Benefits of coding standards






49. Error and exception management






50. Vulnerabilities repositories