Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 54 páginas
Examen

CSST Exam Preparation: Advanced Certified Software Security Tester (CSST) - Comprehensive Practice Examination

Document preview thumbnail
Vista previa 4 fuera de 54 páginas

CSST Exam Preparation: Advanced Certified Software Security Tester (CSST) - Comprehensive Practice Examination

Vista previa del contenido

CSST Exam Preparation: Advanced Certified
Software Security Tester (CSST) - Comprehensive
Practice Examination

Examination Overview
Certification: Certified Software Security Tester (CSST)
Level: Advanced / Expert
Target Audience: Security Professionals, Penetration Testers, Security Architects,
DevSecOps Engineers, and Senior QA Engineers specializing in Application Security
Total Questions: 150 Multiple-Choice Questions
Recommended Time: 180 Minutes (3 Hours)
Passing Score: 70% (105 Correct Answers)
Domain Coverage: Security Risk Management (25%), Asset Identification &
Classification (15%), Security Policies & Governance (20%), Security Auditing &
Assessment (20%), Testing Methodologies (10%), Information Assurance &
Organizational Context (10%)




Domain 1: Advanced Security Risk Management and
Threat Analysis (Questions 1-35)
1. In the context of Advanced Persistent Threats (APTs), which of the following
characteristics most accurately distinguishes them from standard cyber attacks?

A) They exclusively target financial institutions and use only zero-day exploits
B) They are characterized by prolonged, targeted operations with significant
resources and sophisticated techniques
C) They rely solely on social engineering tactics without technical exploitation
D) They are typically conducted by script kiddies using automated tools

Correct Answer: B
Rationale: APTs are distinguished by their sophisticated, sustained nature where threat

,actors maintain long-term access using advanced techniques. They are well-resourced,
targeted, and persistent, unlike single-event attacks conducted by less sophisticated
actors.

2. Which of the following represents the MOST comprehensive risk assessment
approach when evaluating a complex distributed system?

A) Performing a quantitative risk analysis using Annualized Loss Expectancy (ALE)
calculations
B) Conducting a qualitative risk assessment with stakeholder interviews
C) Implementing a hybrid approach combining quantitative metrics with
qualitative expert judgment
D) Relying solely on automated vulnerability scanning results

Correct Answer: C
Rationale: Complex distributed systems require a hybrid approach that combines the
numerical precision of quantitative analysis with the contextual insights of qualitative
assessment. This provides a more comprehensive understanding of risks in
multifaceted environments where pure quantitative or qualitative approaches alone
are insufficient.

3. The concept of "risk aggregation" in enterprise security testing refers to:

A) Adding individual risk scores to calculate total organizational risk
B) The process of combining and correlating risks across different business units
and systems
C) Multiplying risk probabilities by impacts for each asset
D) The practice of ignoring low-level risks in favor of high-level ones

Correct Answer: B
Rationale: Risk aggregation involves combining and correlating risks across an
organization to understand cumulative exposure. Individual risks can interact and
compound, creating systemic risk that exceeds the sum of individual risk scores.

4. When performing a threat modeling exercise using the STRIDE methodology,
which threat category addresses the scenario where an attacker modifies data in
transit?

, A) Spoofing
B) Tampering
C) Repudiation
D) Information Disclosure

Correct Answer: B
Rationale: STRIDE categorizes tampering as unauthorized modification of data. This
includes data modification in transit, at rest, or during processing. Tampering attacks
compromise data integrity.

5. In the DREAD risk assessment model, the "Discoverability" component
primarily evaluates:

A) How easy it is for attackers to find the vulnerability
B) How much damage the vulnerability could cause
C) How many users are affected by the vulnerability
D) How easy it is to exploit the vulnerability

Correct Answer: A
Rationale: In the DREAD model, Discoverability measures how easy it is for an attacker
to identify and find the vulnerability. This factor is particularly important because even
severe vulnerabilities that are difficult to discover may pose lower overall risk than
easily found ones.

6. What is the primary limitation of using Common Vulnerability Scoring System
(CVSS) v3.1 scores in isolation for risk prioritization?

A) CVSS scores are too difficult to calculate accurately
B) CVSS does not account for organizational context and business impact
C) CVSS only applies to network vulnerabilities
D) CVSS scores cannot be compared across different vulnerability types

Correct Answer: B
Rationale: CVSS provides a standardized severity score based on technical
characteristics, but it does not incorporate organizational context such as asset
criticality, business impact, or existing compensating controls. Organizations must
supplement CVSS with contextual risk factors.

, 7. Which of the following best describes the relationship between threat
intelligence and security testing?

A) Threat intelligence replaces the need for security testing
B) Threat intelligence informs testing priorities by identifying current attack
patterns and techniques
C) Threat intelligence is only useful after a security breach occurs
D) Threat intelligence and security testing are unrelated activities

Correct Answer: B
Rationale: Threat intelligence provides actionable information about current threats,
attack patterns, and adversary techniques, which helps security testers focus on the
most relevant and current attack vectors during testing.

8. In Bayesian risk analysis, the posterior probability of a security incident is
calculated by:

A) Multiplying prior probability by likelihood of evidence
B) Dividing prior probability by the likelihood of evidence
C) Combining prior probability with new evidence using Bayes' theorem
D) Calculating the absolute frequency of incidents

Correct Answer: C
Rationale: Bayesian risk analysis updates prior probabilities with new evidence using
Bayes' theorem to calculate posterior probabilities. This approach allows for dynamic
risk assessment as new threat intelligence and security events emerge.

9. The "Confidentiality, Integrity, and Availability" (CIA) triad, when applied to risk
assessment, requires that:

A) All three components must always be equally prioritized
B) The relative importance of each component varies based on business
requirements and data classification
C) Availability is always the most critical component
D) Confidentiality always takes precedence over other components

Información del documento

Subido en
1 de julio de 2026
Número de páginas
54
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$24.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
wise254
5.0
(571)
Vendido
61
Seguidores
5
Artículos
2980
Última venta
3 días hace


Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes