Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Availability






2. Phsychological acceptability






3. ISO/IEC 27003






4. Operation Controls






5. Security Risk Management Discipline






6. DREAD






7. Configurations Parameters Management






8. Least common mechanism






9. Multifactor authentication






10. FIPS 197 (Advance Cryptographic standards - AES)






11. Threat






12. Common best practices significant to Sofware Security






13. ISO/IEC 15408






14. Vulnerability






15. ISO/IEC 9216






16. Properties of secure software






17. Core Security Concept






18. Security Standards






19. Examples of Security Standards






20. Least privilege






21. Clipping level






22. OWASP development guide






23. ISO/IEC 27001:2005






24. Single Loss Expectancy (SLE)






25. Non Repudiation






26. Software security risk management methodologies






27. NIST standards related to software security






28. Access Matrix model


29. ISO/IEC 27005:2008






30. Management Controls






31. Authorization






32. Open design






33. Counter measures






34. Develop hack resilient software






35. Integrity






36. Challenges in implementing auditing/logging






37. Annual Rate of Occurence (ARO)






38. Popular guides developed by OWASP






39. Benefits of coding standards






40. Categories of controls






41. Security Controls






42. Session Management






43. Implementation challenges






44. FIPS140-2 (Security requirement for cryptographic modules)






45. Risk management process






46. ISO/IEC 27002:2005






47. ISO/IEC 21827:2008






48. Technical Controls






49. General security concept






50. Safeguards