CSSLP Test with all Correct & 100% Verified Answers |
Actual Complete Update |Already Graded A+
Security commensurate with the risk and the magnitude of harm resulting from the loss,
misuse, or unauthorized access to or modification of information. Source: OMB Circular A-130
✔Correct Answer-Adequate Security
Ensuring timely and reliable access to and use of information by authorized users. ✔Correct
Answer-Availability
A service provider who offers customers storage or software solutions available via a public
network, usually the internet. ✔Correct Answer-Cloud Service Providers
Denial of Service (DoS) attack is achieved via the prevention of authorized access to resources or
the delaying of time-critical operations. ✔Correct Answer-DoS
A cryptographic operation which, when implemented correctly, can provide assurance for data
integrity, origin, and non-repudiation. This normally requires the use of a Digital Certificate.
✔Correct Answer-Digital Signature
In information systems terms, Disaster Recovery (DR) refers to the activities necessary to restore
IT and communications services to an organization during and after an outage, disruption, or
disturbance of any kind or scale. ✔Correct Answer-DR
A Distributed Denial of Service (DDoS) attack is a type of DoS attack that uses many sources of
attack traffic. A DoS attack uses a single source of attack traffic. Attackers often use botnets to
carry out DDoS attacks. ✔Correct Answer-DDoS
Demonstrates the principle that overly complex approaches will not necessarily enhance
security as opposed to relatively straightforward and simple approaches. ✔Correct Answer-
Economy of Mechanism
Switching to a redundant or standby computer server, system, hardware component, or
network upon the failure or abnormal termination of the previously active application, server,
system, hardware component, or network. ✔Correct Answer-Failover
The system remains working as expected even when some of its components are failing.
✔Correct Answer-Fault Tolerance
A form of one-way encryption that uses a mathematical function to create a fixed length binary
output from a variable length binary input. ✔Correct Answer-Hashing
,Groups of computers that support server applications that can be reliably utilized with a
minimum of downtime. They operate by using high-availability software to harness redundant
computers in groups or clusters that provide continued service when system components fail.
✔Correct Answer-High-Availability Clusters
A technical and business strategy for designing adaptable systems including software. MOSA
requires that major interface points within systems are modular and embrace widely supported
standards. ✔Correct Answer-Modular Open Systems Approach (MOSA)
Protects against an individual falsely denying having performed a particular action, including the
capability to determine whether a given individual took a particular action such as creating
information, sending a message, approving information, and receiving a message. ✔Correct
Answer-Nonrepudiation
Open-Source Software (OSS) is a category of software whose source code and other design
information is made publicly available for inspection, testing, assessment, and use. ✔Correct
Answer-OSS
A way to describe the complexity of a password mathematically. Password entropy determines
how difficult guessing a password can be by calculating a 50-percent chance of guessing a
password based on password length and possible characters. ✔Correct Answer-Password
Entropy
Recovery Point Objective (RPO) is a measure of how much data the organization can lose before
the organization is no longer viable. ✔Correct Answer-RPO
Recovery Time Objective (RTO) refers to the target time set for recovering from any
interruption. ✔Correct Answer-RTO
Continuing the running of an organization even with the absence/failure of one important
component. ✔Correct Answer-Redundancy
A Redundant Array of Independent Disks (RAID) is a data storage virtualization technology that
combines multiple physical disk-drive components into a single logical unit for the purposes of
data redundancy, performance improvement, or both. ✔Correct Answer-RAID
The process of storing data in more than one site or node. ✔Correct Answer-Replication
Primarily associated with organizations that assign clearance levels to all users and classification
levels to all assets; restricts users with the same clearance level from sharing information unless
they are working on the same effort. ✔Correct Answer-Need-to-Know
The periodical rotation of employees in critical or financial roles to prevent nefarious activities
from taking place across time without collusion. ✔Correct Answer-Rotation of Duties
, The practice of ensuring that no organizational process can be completed by a single person;
forces collusion as a means to reduce insider threats. ✔Correct Answer-Separation of Duties
Software Development Life Cycle (SDLC) refers to a formal or informal methodology for
designing, creating, and maintaining software (including code built in hardware). ✔Correct
Answer-SDLC
Transport Layer Security (TLS) is a set of protocols used to secure communications in a wide
variety of online transactions, such as financial transactions, healthcare transactions, and social
transactions. ✔Correct Answer-TLS
The amount of effort necessary to break a cryptographic system, usually measured in total
elapsed time. ✔Correct Answer-Work Factor
A collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least
privilege per-request access decisions in information systems and services in the face of a
network viewed as compromised ✔Correct Answer-Zero Trust
Development that uses small team environments and focuses on collaborative, iterative
learning, building, testing, and deployment of capabilities to operational use. ✔Correct
Answer-Agile Development
An Application Programming Interface (API) is a set of routines, standards, protocols, and tools
for building software applications to access a web-based software application or web tool.
✔Correct Answer-API
The Building Security in Maturity Model (BSIMM) is a descriptive model that provides a baseline
of observed software security initiatives and activities from a collection of software
development shops ✔Correct Answer-BSIMM
Business Continuity Plan (BCP) refers to a collective set of predetermined instructions or
procedures that describe how an organization's mission/business processes will be sustained
during and after a significant disruption. ✔Correct Answer-BCP
Business Impact Analysis (BIA) refers to a type of analysis of an information system's
requirements, functions, and interdependencies used to characterize system contingency
requirements and priorities in the event of a significant disruption. ✔Correct Answer-BIA
The Center for Internet Security (CIS) is a nonprofit organization created in 2000 with a mission,
according to its website, to "make the connected world a safer place by developing, validating,
and promoting timely best practice solutions...to protect against pervasive cyber threats." It has
developed standards and technology tools toward the implementation and management of
cyber defenses. ✔Correct Answer-CIS
Actual Complete Update |Already Graded A+
Security commensurate with the risk and the magnitude of harm resulting from the loss,
misuse, or unauthorized access to or modification of information. Source: OMB Circular A-130
✔Correct Answer-Adequate Security
Ensuring timely and reliable access to and use of information by authorized users. ✔Correct
Answer-Availability
A service provider who offers customers storage or software solutions available via a public
network, usually the internet. ✔Correct Answer-Cloud Service Providers
Denial of Service (DoS) attack is achieved via the prevention of authorized access to resources or
the delaying of time-critical operations. ✔Correct Answer-DoS
A cryptographic operation which, when implemented correctly, can provide assurance for data
integrity, origin, and non-repudiation. This normally requires the use of a Digital Certificate.
✔Correct Answer-Digital Signature
In information systems terms, Disaster Recovery (DR) refers to the activities necessary to restore
IT and communications services to an organization during and after an outage, disruption, or
disturbance of any kind or scale. ✔Correct Answer-DR
A Distributed Denial of Service (DDoS) attack is a type of DoS attack that uses many sources of
attack traffic. A DoS attack uses a single source of attack traffic. Attackers often use botnets to
carry out DDoS attacks. ✔Correct Answer-DDoS
Demonstrates the principle that overly complex approaches will not necessarily enhance
security as opposed to relatively straightforward and simple approaches. ✔Correct Answer-
Economy of Mechanism
Switching to a redundant or standby computer server, system, hardware component, or
network upon the failure or abnormal termination of the previously active application, server,
system, hardware component, or network. ✔Correct Answer-Failover
The system remains working as expected even when some of its components are failing.
✔Correct Answer-Fault Tolerance
A form of one-way encryption that uses a mathematical function to create a fixed length binary
output from a variable length binary input. ✔Correct Answer-Hashing
,Groups of computers that support server applications that can be reliably utilized with a
minimum of downtime. They operate by using high-availability software to harness redundant
computers in groups or clusters that provide continued service when system components fail.
✔Correct Answer-High-Availability Clusters
A technical and business strategy for designing adaptable systems including software. MOSA
requires that major interface points within systems are modular and embrace widely supported
standards. ✔Correct Answer-Modular Open Systems Approach (MOSA)
Protects against an individual falsely denying having performed a particular action, including the
capability to determine whether a given individual took a particular action such as creating
information, sending a message, approving information, and receiving a message. ✔Correct
Answer-Nonrepudiation
Open-Source Software (OSS) is a category of software whose source code and other design
information is made publicly available for inspection, testing, assessment, and use. ✔Correct
Answer-OSS
A way to describe the complexity of a password mathematically. Password entropy determines
how difficult guessing a password can be by calculating a 50-percent chance of guessing a
password based on password length and possible characters. ✔Correct Answer-Password
Entropy
Recovery Point Objective (RPO) is a measure of how much data the organization can lose before
the organization is no longer viable. ✔Correct Answer-RPO
Recovery Time Objective (RTO) refers to the target time set for recovering from any
interruption. ✔Correct Answer-RTO
Continuing the running of an organization even with the absence/failure of one important
component. ✔Correct Answer-Redundancy
A Redundant Array of Independent Disks (RAID) is a data storage virtualization technology that
combines multiple physical disk-drive components into a single logical unit for the purposes of
data redundancy, performance improvement, or both. ✔Correct Answer-RAID
The process of storing data in more than one site or node. ✔Correct Answer-Replication
Primarily associated with organizations that assign clearance levels to all users and classification
levels to all assets; restricts users with the same clearance level from sharing information unless
they are working on the same effort. ✔Correct Answer-Need-to-Know
The periodical rotation of employees in critical or financial roles to prevent nefarious activities
from taking place across time without collusion. ✔Correct Answer-Rotation of Duties
, The practice of ensuring that no organizational process can be completed by a single person;
forces collusion as a means to reduce insider threats. ✔Correct Answer-Separation of Duties
Software Development Life Cycle (SDLC) refers to a formal or informal methodology for
designing, creating, and maintaining software (including code built in hardware). ✔Correct
Answer-SDLC
Transport Layer Security (TLS) is a set of protocols used to secure communications in a wide
variety of online transactions, such as financial transactions, healthcare transactions, and social
transactions. ✔Correct Answer-TLS
The amount of effort necessary to break a cryptographic system, usually measured in total
elapsed time. ✔Correct Answer-Work Factor
A collection of concepts and ideas designed to minimize uncertainty in enforcing accurate, least
privilege per-request access decisions in information systems and services in the face of a
network viewed as compromised ✔Correct Answer-Zero Trust
Development that uses small team environments and focuses on collaborative, iterative
learning, building, testing, and deployment of capabilities to operational use. ✔Correct
Answer-Agile Development
An Application Programming Interface (API) is a set of routines, standards, protocols, and tools
for building software applications to access a web-based software application or web tool.
✔Correct Answer-API
The Building Security in Maturity Model (BSIMM) is a descriptive model that provides a baseline
of observed software security initiatives and activities from a collection of software
development shops ✔Correct Answer-BSIMM
Business Continuity Plan (BCP) refers to a collective set of predetermined instructions or
procedures that describe how an organization's mission/business processes will be sustained
during and after a significant disruption. ✔Correct Answer-BCP
Business Impact Analysis (BIA) refers to a type of analysis of an information system's
requirements, functions, and interdependencies used to characterize system contingency
requirements and priorities in the event of a significant disruption. ✔Correct Answer-BIA
The Center for Internet Security (CIS) is a nonprofit organization created in 2000 with a mission,
according to its website, to "make the connected world a safer place by developing, validating,
and promoting timely best practice solutions...to protect against pervasive cyber threats." It has
developed standards and technology tools toward the implementation and management of
cyber defenses. ✔Correct Answer-CIS