Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Open design






2. Implementation challenges






3. Single Loss Expectancy (SLE)






4. Authorization






5. FIPS 197 (Advance Cryptographic standards - AES)






6. Take-Grant Model






7. Management Controls






8. Residual Risk






9. Threat






10. Examples of Security Standards






11. Total Risk






12. OWASP development guide






13. Integrity






14. Vulnerability






15. Counter measures






16. Categories of controls






17. Least privilege






18. Information Security Models






19. Multifactor authentication






20. Clipping level






21. Software security risk management methodologies






22. OCTAVE






23. Flaw Hypothesis Method (FHM)






24. Least common mechanism






25. Security Policies


26. OWASP testing guide






27. ISO/IEC 27001:2005






28. Vulnerabilities repositories






29. Access Matrix model


30. Accountability






31. Availability






32. General security concept






33. Holistic Security in software






34. Annual Loss Expectancy (ALE)






35. Security Standards






36. NIST standards related to software security






37. Benefits of coding standards






38. Security Risk Management Discipline






39. OWASP Code Review Guide






40. Security profile of a software






41. Non Repudiation






42. Security design principles






43. ISO/IEC 15408






44. STRIDE






45. Common best practices significant to Sofware Security






46. ISO/IEC 27003






47. Auditing






48. Session Management






49. FIPS 201






50. Operation Controls