Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. PCI DSS






2. Security profile of a software






3. Clipping level






4. Implementation challenges






5. Vulnerabilities repositories






6. Take-Grant Model






7. ISO/IEC 27005:2008






8. Annual Rate of Occurence (ARO)






9. ISO/IEC 21827:2008






10. Management Controls






11. ISO/IEC 15408






12. Authentication






13. Auditing






14. STRIDE






15. ISO/IEC 27001:2005






16. Holistic Security in software






17. Least privilege






18. Economy of mechanism






19. Examples of Security Standards






20. Accountability






21. Operation Controls






22. ISO/IEC 27006:2007






23. Least common mechanism






24. Core Security Concept






25. Error and exception management






26. Security Standards






27. Confidentiality






28. Configurations Parameters Management






29. Benefits of coding standards






30. Authorization






31. OWASP Code Review Guide






32. Counter measures






33. ISO/IEC 27003






34. Challenges in implementing auditing/logging






35. Popular guides developed by OWASP






36. Safeguards






37. Security Policies


38. Single point failure






39. Complete mediation






40. Residual Risk






41. DREAD






42. FIPS140-2 (Security requirement for cryptographic modules)






43. Security Controls






44. Single Loss Expectancy (SLE)






45. Properties of secure software






46. Open design






47. FIPS 201






48. OWASP development guide






49. Compartmentalization






50. Access Matrix model