CSSLP Domain 7 - Secure Software Testing with all Correct
& 100% Verified Answers |Latest Version |Already
Graded A+
Examples of secrets that need to be protected during the deployment and operation of
software include the following except what?
A. Keys/certificates
B. Configuration elements such as connection paths
C. Source code
D. Credentials for connecting to other systems ✔Correct Answer-C. When deploying, the
source code is no longer available—an executable of the object code is deployed, not the source
code.
2. What does build artifact verification ensure?
A. The integrity of a module
B. The authority and integrity of modules
C. Code is the correct size
D. All of the above ✔Correct Answer-A. Build artifact verification involves determining that
the authentication and integrity of build artifacts are true and correct.
3. Risk analysis involves examining what properties that must be considered to stay secure
within acceptable limits?
A. Implicit security requirements
B. Explicit security requirements
C. Degree of software complexity
D. All of the above ✔Correct Answer-D. Risks comprise a range of properties that must be
considered in order to stay secure within acceptable limits. Those properties include
• Implicit and explicit safety requirements
, • Implicit and explicit security requirements
• Degree of software complexity
• Performance factors
• Reliability factors
4. Risk acceptance assessments should always embody a methodology for data collection that is
what?
A. Simple to use
B. Repeatable
C. Defined by the threat under consideration
D. Fast ✔Correct Answer-B. Risk acceptance assessments should always embody a commonly
accepted and repeatable methodology for data collection that produces reliable and concrete
evidence that can be independently verified as correct.
5. Which of the following represents what could be typical secrets ingested by an application in
operation?
A. Security token data
B. SSH keys
C. Certificates
D. All of the above ✔Correct Answer-D. All of the above are typical security secrets that can
be ingested during program operation.
6. Continuous integration/continuous development (CI/CD) is another name for?
A. A method of deploying software developed by Microsoft
B. DevOps
C. A structured means of managing requirements in deployment for government customers
D. A manual system for validation and verification ✔Correct Answer-B. Another name for
DevOps is continuous integration/continuous development (CI/CD).
& 100% Verified Answers |Latest Version |Already
Graded A+
Examples of secrets that need to be protected during the deployment and operation of
software include the following except what?
A. Keys/certificates
B. Configuration elements such as connection paths
C. Source code
D. Credentials for connecting to other systems ✔Correct Answer-C. When deploying, the
source code is no longer available—an executable of the object code is deployed, not the source
code.
2. What does build artifact verification ensure?
A. The integrity of a module
B. The authority and integrity of modules
C. Code is the correct size
D. All of the above ✔Correct Answer-A. Build artifact verification involves determining that
the authentication and integrity of build artifacts are true and correct.
3. Risk analysis involves examining what properties that must be considered to stay secure
within acceptable limits?
A. Implicit security requirements
B. Explicit security requirements
C. Degree of software complexity
D. All of the above ✔Correct Answer-D. Risks comprise a range of properties that must be
considered in order to stay secure within acceptable limits. Those properties include
• Implicit and explicit safety requirements
, • Implicit and explicit security requirements
• Degree of software complexity
• Performance factors
• Reliability factors
4. Risk acceptance assessments should always embody a methodology for data collection that is
what?
A. Simple to use
B. Repeatable
C. Defined by the threat under consideration
D. Fast ✔Correct Answer-B. Risk acceptance assessments should always embody a commonly
accepted and repeatable methodology for data collection that produces reliable and concrete
evidence that can be independently verified as correct.
5. Which of the following represents what could be typical secrets ingested by an application in
operation?
A. Security token data
B. SSH keys
C. Certificates
D. All of the above ✔Correct Answer-D. All of the above are typical security secrets that can
be ingested during program operation.
6. Continuous integration/continuous development (CI/CD) is another name for?
A. A method of deploying software developed by Microsoft
B. DevOps
C. A structured means of managing requirements in deployment for government customers
D. A manual system for validation and verification ✔Correct Answer-B. Another name for
DevOps is continuous integration/continuous development (CI/CD).