Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Annual Loss Expectancy (ALE)






2. Phsychological acceptability






3. Single point failure






4. OWASP testing guide






5. Least common mechanism






6. ISO /IEC 27000:2009






7. Risk management process






8. Confidentiality






9. Benefits of coding standards






10. FIPS140-2 (Security requirement for cryptographic modules)






11. Non Repudiation






12. NIST standards related to software security






13. Annual Rate of Occurence (ARO)






14. DREAD






15. Information Security Models






16. Auditing






17. Common best practices significant to Sofware Security






18. Vulnerability






19. Authorization






20. Properties of secure software






21. ISO/IEC 27006:2007






22. Economy of mechanism






23. Examples of Security Standards






24. Operation Controls






25. Authentication






26. Least privilege






27. Configurations Parameters Management






28. Error and exception management






29. ISO/IEC 27005:2008






30. Implementation challenges






31. Management Controls






32. Take-Grant Model






33. Holistic Security in software






34. Security Risk Management Discipline






35. EALs levels






36. PCI DSS






37. ISO/IEC 15408






38. ISO/IEC 27003






39. Counter measures






40. Security Standards






41. Single Loss Expectancy (SLE)






42. OWASP development guide






43. Flaw Hypothesis Method (FHM)






44. Total Risk






45. Technical Controls






46. Complete mediation






47. Session Management






48. Develop hack resilient software






49. Safeguards






50. After identification step is...