Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Compartmentalization






2. Categories of controls






3. Safeguards






4. Least common mechanism






5. ISO/IEC 27006:2007






6. OWASP development guide






7. Auditing






8. OWASP Top 10






9. Core Security Concept






10. Popular guides developed by OWASP






11. Security Standards






12. Authentication






13. Properties of secure software






14. Confidentiality






15. Security profile of a software






16. ISO/IEC 27001:2005






17. Annual Loss Expectancy (ALE)






18. FIPS 197 (Advance Cryptographic standards - AES)






19. Session Management






20. Common best practices significant to Sofware Security






21. Clipping level






22. Risk management process






23. Phsychological acceptability






24. Develop hack resilient software






25. Security Risk Management Discipline






26. Management Controls






27. OWASP Code Review Guide






28. ISO/IEC 27005:2008






29. Benefits of coding standards






30. Annual Rate of Occurence (ARO)






31. NIST standards related to software security






32. Authorization






33. Configurations Parameters Management






34. Open design






35. Error and exception management






36. After identification step is...






37. Integrity






38. Least privilege






39. Take-Grant Model






40. DREAD






41. ISO/IEC 27003






42. Single Loss Expectancy (SLE)






43. Multifactor authentication






44. ISO/IEC 9216






45. Threat






46. Holistic Security in software






47. Non Repudiation






48. Challenges in implementing auditing/logging






49. Operation Controls






50. Availability