Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Annual Loss Expectancy (ALE)






2. FIPS140-2 (Security requirement for cryptographic modules)






3. Information Security Models






4. After identification step is...






5. ISO/IEC 27002:2005






6. Security design principles






7. Open design






8. Security Policies


9. Accountability






10. Properties of secure software






11. Technical Controls






12. Multifactor authentication






13. Flaw Hypothesis Method (FHM)






14. Availability






15. ISO/IEC 15408






16. Single Loss Expectancy (SLE)






17. Vulnerability






18. Compartmentalization






19. Economy of mechanism






20. EALs levels






21. Counter measures






22. Software security risk management methodologies






23. Access Matrix model


24. Security Risk Management Discipline






25. Core Security Concept






26. Security Controls






27. Total Risk






28. ISO/IEC 27005:2008






29. Authentication






30. Security profile of a software






31. NIST standards related to software security






32. OWASP development guide






33. Common best practices significant to Sofware Security






34. Safeguards






35. Implementation challenges






36. Residual Risk






37. Management Controls






38. Take-Grant Model






39. Exposure factor (EF)






40. Confidentiality






41. Categories of controls






42. Develop hack resilient software






43. Integrity






44. OWASP Code Review Guide






45. FIPS 197 (Advance Cryptographic standards - AES)






46. Holistic Security in software






47. Complete mediation






48. Session Management






49. Security Standards






50. Configurations Parameters Management