Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Access Matrix model


2. Holistic Security in software






3. STRIDE






4. Popular guides developed by OWASP






5. Single Loss Expectancy (SLE)






6. Core Security Concept






7. Develop hack resilient software






8. FIPS140-2 (Security requirement for cryptographic modules)






9. Residual Risk






10. Non Repudiation






11. FIPS 197 (Advance Cryptographic standards - AES)






12. Clipping level






13. OWASP testing guide






14. Security Standards






15. Total Risk






16. Vulnerability






17. ISO /IEC 27000:2009






18. Flaw Hypothesis Method (FHM)






19. ISO/IEC 27006:2007






20. Implementation challenges






21. Security design principles






22. Configurations Parameters Management






23. Management Controls






24. ISO/IEC 27005:2008






25. OWASP Code Review Guide






26. ISO/IEC 15408






27. Security Policies


28. Open design






29. Benefits of coding standards






30. Error and exception management






31. Confidentiality






32. FIPS 201






33. Challenges in implementing auditing/logging






34. Software security risk management methodologies






35. OWASP Top 10






36. Risk management process






37. Threat






38. Annual Loss Expectancy (ALE)






39. Availability






40. Common best practices significant to Sofware Security






41. Session Management






42. NIST standards related to software security






43. ISO/IEC 21827:2008






44. DREAD






45. Least privilege






46. Integrity






47. After identification step is...






48. Economy of mechanism






49. Least common mechanism






50. Exposure factor (EF)