CSSLP: Certified Secure Software Lifecycle Professional
Test with all Correct & 100% Verified Answers |
Guaranteed to Pass
Confidentiality ✔Correct Answer-The prevention of the disclosure of information to
unauthorized parties
Integrity ✔Correct Answer-The protection of data from unauthorized alteration
Availability ✔Correct Answer-The assurance that authorized users are able to access the
system
Authentication ✔Correct Answer-Determining a user's identity, and ensuring they are who
they say they are.
Type 1 Authentication ✔Correct Answer-Determining identity using "something you know"
Type 2 Authentication ✔Correct Answer-Determining identity using "something you have"
Type 3 Authentication ✔Correct Answer-Determining identity using "something you are"
Multifactor Authentication ✔Correct Answer-Determining identity using multiple
authentication types
Authorization ✔Correct Answer-Allowing or denying user access based on user identity
Non-Repudiation ✔Correct Answer-The withholding of deniability, or making sure there's
proof that users did what they did
Accounting ✔Correct Answer-The recording of actions and the users performing them
AAA ✔Correct Answer-Fulfillment of security requirements using authentication,
authorization and auditing
Basic Authentication ✔Correct Answer-Establishing identity using a plaintext password
Salted Hash ✔Correct Answer-A server-side representation of a password in which the
password is concatenated with a secret before hashing
Federated ID System ✔Correct Answer-Allows a user to log in to a system using a different,
trusted system
, OpenID ✔Correct Answer-A protocol that allows an application to use a third-party service as
an identity provider
OAuth ✔Correct Answer-A protocol that allows users to access resources without disclosing
credentials to the application using tokens
Good Enough Security ✔Correct Answer-The principle that security is not absolute, and
should be tailored to fit a given threat model
Least Privilege ✔Correct Answer-Subjects should be given only those privileges that allow
them to perform their required duties
Separation of Duties ✔Correct Answer-Requiring multiple individuals to act on a task such
that abuse by a single individual is discouraged
Defense in Depth ✔Correct Answer-The use of overlapping systems of different control
mechanisms, effectively avoiding a single point of failure
Fail Safe ✔Correct Answer-Failure of one or more components should leave the system in a
secure state
Economy of Mechanism ✔Correct Answer-All else equal, simpler programs are less error-
prone and therefore less susceptible to bugs or esoteric vulnerabilities
Complete Mediation ✔Correct Answer-Authorization is verified each time a subject attempts
to access or modify an object
Open Design ✔Correct Answer-Discouraging "security through obscurity" by taking away the
obscurity
Least Common Mechanism ✔Correct Answer-Avoiding the repeated use of a security
mechanism that protects critical resources
Psychological Acceptability ✔Correct Answer-Preventing users from circumventing security
measures by making the security measures sufficiently easy to follow
Mandatory Access Control (MAC) ✔Correct Answer-Objects are restricted by the system and
subjects may not modify these restrictions
Discretionary Access Control (DAC) ✔Correct Answer-Subjects with sufficient permissions can
control other subjects' access to objects
Test with all Correct & 100% Verified Answers |
Guaranteed to Pass
Confidentiality ✔Correct Answer-The prevention of the disclosure of information to
unauthorized parties
Integrity ✔Correct Answer-The protection of data from unauthorized alteration
Availability ✔Correct Answer-The assurance that authorized users are able to access the
system
Authentication ✔Correct Answer-Determining a user's identity, and ensuring they are who
they say they are.
Type 1 Authentication ✔Correct Answer-Determining identity using "something you know"
Type 2 Authentication ✔Correct Answer-Determining identity using "something you have"
Type 3 Authentication ✔Correct Answer-Determining identity using "something you are"
Multifactor Authentication ✔Correct Answer-Determining identity using multiple
authentication types
Authorization ✔Correct Answer-Allowing or denying user access based on user identity
Non-Repudiation ✔Correct Answer-The withholding of deniability, or making sure there's
proof that users did what they did
Accounting ✔Correct Answer-The recording of actions and the users performing them
AAA ✔Correct Answer-Fulfillment of security requirements using authentication,
authorization and auditing
Basic Authentication ✔Correct Answer-Establishing identity using a plaintext password
Salted Hash ✔Correct Answer-A server-side representation of a password in which the
password is concatenated with a secret before hashing
Federated ID System ✔Correct Answer-Allows a user to log in to a system using a different,
trusted system
, OpenID ✔Correct Answer-A protocol that allows an application to use a third-party service as
an identity provider
OAuth ✔Correct Answer-A protocol that allows users to access resources without disclosing
credentials to the application using tokens
Good Enough Security ✔Correct Answer-The principle that security is not absolute, and
should be tailored to fit a given threat model
Least Privilege ✔Correct Answer-Subjects should be given only those privileges that allow
them to perform their required duties
Separation of Duties ✔Correct Answer-Requiring multiple individuals to act on a task such
that abuse by a single individual is discouraged
Defense in Depth ✔Correct Answer-The use of overlapping systems of different control
mechanisms, effectively avoiding a single point of failure
Fail Safe ✔Correct Answer-Failure of one or more components should leave the system in a
secure state
Economy of Mechanism ✔Correct Answer-All else equal, simpler programs are less error-
prone and therefore less susceptible to bugs or esoteric vulnerabilities
Complete Mediation ✔Correct Answer-Authorization is verified each time a subject attempts
to access or modify an object
Open Design ✔Correct Answer-Discouraging "security through obscurity" by taking away the
obscurity
Least Common Mechanism ✔Correct Answer-Avoiding the repeated use of a security
mechanism that protects critical resources
Psychological Acceptability ✔Correct Answer-Preventing users from circumventing security
measures by making the security measures sufficiently easy to follow
Mandatory Access Control (MAC) ✔Correct Answer-Objects are restricted by the system and
subjects may not modify these restrictions
Discretionary Access Control (DAC) ✔Correct Answer-Subjects with sufficient permissions can
control other subjects' access to objects