Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Session Management






2. Confidentiality






3. Examples of Security Standards






4. ISO/IEC 27006:2007






5. NIST standards related to software security






6. Counter measures






7. Auditing






8. Multifactor authentication






9. Software security risk management methodologies






10. Security Policies


11. Error and exception management






12. FIPS 197 (Advance Cryptographic standards - AES)






13. OCTAVE






14. Total Risk






15. Exposure factor (EF)






16. Common best practices significant to Sofware Security






17. STRIDE






18. Annual Rate of Occurence (ARO)






19. ISO/IEC 21827:2008






20. Authorization






21. EALs levels






22. PCI DSS






23. Management Controls






24. ISO /IEC 27000:2009






25. Technical Controls






26. Configurations Parameters Management






27. Risk management process






28. After identification step is...






29. Single point failure






30. Security design principles






31. Availability






32. ISO/IEC 9216






33. Security Risk Management Discipline






34. Clipping level






35. General security concept






36. OWASP Code Review Guide






37. Open design






38. ISO/IEC 27003






39. Operation Controls






40. Benefits of coding standards






41. ISO/IEC 27005:2008






42. OWASP testing guide






43. Security Controls






44. Access Matrix model


45. ISO/IEC 27001:2005






46. Security profile of a software






47. Single Loss Expectancy (SLE)






48. Challenges in implementing auditing/logging






49. Implementation challenges






50. Non Repudiation