Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Vulnerability






2. PCI DSS






3. Security Policies


4. Develop hack resilient software






5. Security profile of a software






6. FIPS140-2 (Security requirement for cryptographic modules)






7. Properties of secure software






8. Multifactor authentication






9. Information Security Models






10. ISO/IEC 15408






11. Error and exception management






12. ISO /IEC 27000:2009






13. Clipping level






14. OCTAVE






15. Auditing






16. Least privilege






17. Configurations Parameters Management






18. Popular guides developed by OWASP






19. ISO/IEC 27005:2008






20. Core Security Concept






21. ISO/IEC 21827:2008






22. Flaw Hypothesis Method (FHM)






23. Least common mechanism






24. NIST standards related to software security






25. General security concept






26. ISO/IEC 27002:2005






27. Compartmentalization






28. Phsychological acceptability






29. Operation Controls






30. Open design






31. OWASP Top 10






32. ISO/IEC 27006:2007






33. Benefits of coding standards






34. ISO/IEC 9216






35. Single Loss Expectancy (SLE)






36. Management Controls






37. Security Standards






38. STRIDE






39. Challenges in implementing auditing/logging






40. Implementation challenges






41. Security Risk Management Discipline






42. Common best practices significant to Sofware Security






43. Counter measures






44. Security design principles






45. EALs levels






46. Vulnerabilities repositories






47. Availability






48. OWASP development guide






49. ISO/IEC 27003






50. After identification step is...