Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 50 pages
Exam (elaborations)

CSST Exam Preparation: Comprehensive Practice Question Bank Certified Software Security Tester (CSST) - Advanced Level Practice Exam

Document preview thumbnail
Preview 4 out of 50 pages

CSST Exam Preparation: Comprehensive Practice Question Bank Certified Software Security Tester (CSST) - Advanced Level Practice Exam

Content preview

CSST Exam Preparation: Comprehensive Practice Question Bank

Certified Software Security Tester (CSST) - Advanced Level Practice
Exam

Exam Overview

The Certified Software Security Tester (CSST) certification validates professional knowledge in
identifying, analyzing, and mitigating security vulnerabilities within software applications. The exam
consists of 50 multiple-choice questions with a 70% passing score (35 correct answers), completed
within 60 minutes . This practice question bank covers all major domains including security risks, asset
identification, risk analysis, security policies, auditing, and the security triad .




Section 1: Security Risks and Asset Identification (Questions 1-25)
1. In the context of software security testing, which of the following best defines a "vulnerability"?

A) An action or event that could potentially cause harm to an organization's assets

B) A weakness in a system's design, implementation, or configuration that could be exploited

C) The likelihood that a threat will materialize and cause damage

D) A measure of the potential financial loss from a security incident

Correct Answer: B
Rationale: A vulnerability is a specific weakness or flaw in a system's security posture that can potentially
be exploited by threats. This is distinct from a threat (option A), which is a potential cause of harm; risk
(option C), which considers likelihood; and impact (option D), which focuses on consequences.

2. Which of the following represents the correct order of the risk management process?

A) Risk identification → Risk analysis → Risk evaluation → Risk treatment

B) Risk analysis → Risk identification → Risk treatment → Risk evaluation

C) Risk evaluation → Risk identification → Risk analysis → Risk treatment

D) Risk treatment → Risk evaluation → Risk identification → Risk analysis

,Correct Answer: A
Rationale: The proper sequence is risk identification (finding risks), risk analysis (understanding nature
and impact), risk evaluation (comparing against criteria), and risk treatment (implementing controls).
This systematic approach ensures comprehensive risk management .

3. What type of asset includes customer databases, trade secrets, and intellectual property?

A) Tangible assets

B) Intangible assets

C) Physical assets

D) Operational assets

Correct Answer: B
Rationale: Intangible assets are non-physical assets that have value, including information assets like
databases, proprietary information, and intellectual property. Tangible assets (option A) are physical
items, while physical assets (option C) specifically refer to hardware and facilities .

4. In security risk assessment, what is the primary purpose of asset identification?

A) To determine the monetary value of all company property

B) To catalog and prioritize resources that need protection

C) To comply with regulatory reporting requirements

D) To create an inventory for insurance purposes

Correct Answer: B
Rationale: Asset identification serves to systematically catalog resources that require protection and
prioritize them based on their importance to the organization. This enables effective allocation of security
resources and controls .

5. Which type of security risk involves unauthorized access to data or systems?

A) Confidentiality risk

B) Integrity risk

C) Availability risk

D) Authentication risk

,Correct Answer: A
Rationale: Confidentiality risks specifically involve unauthorized access to or exposure of sensitive
information. Integrity risks (option B) involve unauthorized modification, availability risks (option C)
involve denial of service, and authentication risks relate to identity verification failures .

6. Which of the following is NOT a component of the security triad (CIA)?

A) Confidentiality

B) Integrity

C) Authorization

D) Availability

Correct Answer: C
Rationale: The security triad consists of Confidentiality, Integrity, and Availability (CIA). Authorization
(option C) is related to access control but is not one of the three core pillars of information security .

7. In the context of security testing, what does the term "threat vector" describe?

A) The path or means by which an attacker gains access to a system

B) The total number of potential attackers targeting a system

C) A measure of the system's vulnerability to attacks

D) The encryption algorithm used to protect data

Correct Answer: A
Rationale: A threat vector is the specific path or methodology an attacker uses to gain unauthorized
access to a system. This includes attack surfaces like email attachments, vulnerable web applications, or
social engineering techniques .

8. Which of the following represents a qualitative risk assessment approach?

A) Calculating potential financial losses in dollars

B) Assigning risk ratings such as "High," "Medium," or "Low"

C) Determining the exact probability of risk occurrence

D) Computing annualized loss expectancy (ALE)

, Correct Answer: B
Rationale: Qualitative risk assessment uses descriptive categories to evaluate risk rather than numerical
values. Options A, C, and D (calculating financial losses, exact probabilities, and ALE) are all elements of
quantitative risk assessment .

9. What is the primary characteristic of an "advanced persistent threat" (APT)?

A) It uses only automated scanning tools

B) It is a single, isolated attack event

C) It is a prolonged, targeted attack with significant resources

D) It focuses exclusively on denial-of-service attacks

Correct Answer: C
Rationale: APTs are sophisticated, sustained attacks where threat actors maintain long-term access to a
target network. They are characterized by being well-resourced, targeted, and persistent, unlike single-
event attacks .

10. Which risk treatment strategy transfers the risk to a third party?

A) Risk avoidance

B) Risk mitigation

C) Risk acceptance

D) Risk transference

Correct Answer: D
Rationale: Risk transference shifts the financial or operational impact of a risk to another entity, such as
purchasing cyber insurance or outsourcing operations to a managed security provider. Avoidance (A)
eliminates the risk, mitigation (B) reduces it, and acceptance (C) acknowledges it without action .

11. In software security, what does the term "attack surface" refer to?

A) The total number of security patches applied

B) The sum of all points where an unauthorized user can enter a system

C) The physical location where servers are housed

D) The number of employees with system access

Document information

Uploaded on
July 1, 2026
Number of pages
50
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$22.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2980
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions