Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Take-Grant Model






2. Security Policies


3. Auditing






4. Annual Loss Expectancy (ALE)






5. Annual Rate of Occurence (ARO)






6. Least common mechanism






7. Single Loss Expectancy (SLE)






8. Session Management






9. ISO/IEC 15408






10. ISO/IEC 27006:2007






11. Availability






12. General security concept






13. Threat






14. Integrity






15. EALs levels






16. Multifactor authentication






17. ISO/IEC 27002:2005






18. Confidentiality






19. ISO/IEC 21827:2008






20. Clipping level






21. Safeguards






22. STRIDE






23. Risk management process






24. Popular guides developed by OWASP






25. Single point failure






26. Configurations Parameters Management






27. Authentication






28. Implementation challenges






29. Software security risk management methodologies






30. Accountability






31. Phsychological acceptability






32. Authorization






33. ISO/IEC 9216






34. Non Repudiation






35. Vulnerability






36. Properties of secure software






37. Security Risk Management Discipline






38. ISO/IEC 27003






39. Common best practices significant to Sofware Security






40. Challenges in implementing auditing/logging






41. Residual Risk






42. Security design principles






43. Exposure factor (EF)






44. ISO/IEC 27005:2008






45. Least privilege






46. Flaw Hypothesis Method (FHM)






47. Security profile of a software






48. Information Security Models






49. Core Security Concept






50. ISO /IEC 27000:2009