Test your basic knowledge |

CSSLP: Certified Secure Software Lifecycle Professional

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Least privilege






2. Single Loss Expectancy (SLE)






3. Availability






4. Software security risk management methodologies






5. FIPS 201






6. Phsychological acceptability






7. OCTAVE






8. Authentication






9. Flaw Hypothesis Method (FHM)






10. OWASP Top 10






11. Security design principles






12. After identification step is...






13. Accountability






14. FIPS140-2 (Security requirement for cryptographic modules)






15. Single point failure






16. Examples of Security Standards






17. OWASP development guide






18. Properties of secure software






19. NIST standards related to software security






20. Confidentiality






21. Safeguards






22. Core Security Concept






23. Common best practices significant to Sofware Security






24. Benefits of coding standards






25. STRIDE






26. FIPS 197 (Advance Cryptographic standards - AES)






27. Holistic Security in software






28. ISO/IEC 27005:2008






29. Security Policies


30. Annual Loss Expectancy (ALE)






31. DREAD






32. General security concept






33. Security profile of a software






34. Management Controls






35. Popular guides developed by OWASP






36. Technical Controls






37. ISO/IEC 15408






38. Authorization






39. Open design






40. ISO/IEC 27002:2005






41. Exposure factor (EF)






42. Counter measures






43. Session Management






44. Compartmentalization






45. ISO/IEC 21827:2008






46. Integrity






47. Multifactor authentication






48. Configurations Parameters Management






49. Complete mediation






50. Error and exception management