• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 36 pages
Exam (elaborations)

CSSLP Test Domain 3 - Secure Software Design with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Document preview thumbnail
Preview 4 out of 36 pages

CSSLP Test Domain 3 - Secure Software Design with all Correct & 100% Verified Answers |Actual Complete Update |Already Graded A+

Content preview

CSSLP Test Domain 3 - Secure Software Design with all
Correct & 100% Verified Answers |Actual Complete
Update |Already Graded A+

What is the OWASP Top 10? ✔Correct Answer-A set of common vulnerable components of
web applications and APIs, ranked in descending order from most commonly exploited

What were the 3 new vulnerability types that were introduced in OWASP Top 10 2021?
✔Correct Answer-- A04: Insecure Design
- A08: Software & Data Integrity Failures
- A10: Server-Side Request Forgery (SSRF)

What are the benefits of Secure by Design adoption? ✔Correct Answer-- Resilient and
recoverable software
- Quality, maintainable software
- Minimal redesign consistency
- Business logic flaws addressed

What is Resilient and Recoverable software? ✔Correct Answer-Decreased likelihood of attack
errors

What is Quality maintainable software? ✔Correct Answer-Software that is less prone to errors

What is Minimal Redesign & Consistency? ✔Correct Answer-A reduced need for redesign,
meaning more consistent software

What is Business logic flaws addressed? ✔Correct Answer-Uncovering design and business
logic flaws through design

Once identified, what should be done with flaws and bugs? ✔Correct Answer-They should be
addressed/mitigated

What are the 6 parts of the STRIDE threat model? ✔Correct Answer-1. Spoofing
2. Tampering
3. Repudiation
4. Info Disclosure
5. DDoS
6. Elevation of Privilege

What are the 5 parts of the DREAD threat model? ✔Correct Answer-1. Damage potential
2. Reproducibility

,3. Exploitability
4. Affected users
5. Discoverability

What is the main method of identifying design flaws in logical software operation? ✔Correct
Answer-Security architecture and design reviews

What are 3 elements are commonly seen across all threat modelling methodologies?
✔Correct Answer-- Threats
- Vulnerabilities/control gaps
- Countermeasures

What is confidentiality design? ✔Correct Answer-Engineering of disclosure protection
mechanisms in software using cryptographic and masking techniques.

What are the 2 methods of cryptography? What algorithms fit under them? ✔Correct
Answer-Overt
> Encryption (Symmetric/Asymmetric)
> Hashing
Covert
> Steganography
> Digital Watermarking

How is Key Exchange and Management performed in Symmetric Algorithms? ✔Correct
Answer-Both the originator and the receiver must have a mechanism in place to share keys
without compromising its secrecy.

Why is Scalability difficult in Symmetric Algorithms? ✔Correct Answer-There needs to be as
many keys as there are senders and recipients

How are keys used in Asymmetric cryptography? ✔Correct Answer-- Only one sender can give
the same public key to all recipients
- Public keys can only be created by the owner of the matching private key
- Recipients of encrypted messages use the matching public key to decrypt messages

What infrastructure is used for Key Exchange and Management in Asymmetric Algorithms?
✔Correct Answer-They use the Public Key Infrastructure (PKI) technique for key identification,
exchange and management. PKI uses digital certificates to make automation of these tasks
possible

Why is Scalability easy in Asymmetric Algorithms? ✔Correct Answer-In asymmetric
cryptography, there only needs to be 2 keys per user; a private and a public one. The public one
can be distributed to anyone who wishes to communicate with the sender, who holds the
private key.

,How do Asymmetric Algorithms ensure Non-Repudiation? ✔Correct Answer-It provides the
receiver, assurance of proof of origin. The sender cannot deny sending any messages when it is
encrypted using their private key

What is the current internationally recognised digital certificate standard, and what different
types are there? ✔Correct Answer-ITU X.509 (v3):
> Personal
> Server
> Extended Validation (EV)
> Software publisher

What are Personal Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Identification of
individuals to authenticate them with a server

What are Server Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Used to identify
servers with a connecting client, over the Secure Socket Layer (SSL)

What are Extended Validation (EV) certificates in X.509 (v3) PKI used for? ✔Correct Answer-
Ensures that sites that users are connecting to are legitimate, as these certificates undergo
more extensive validation than normal certificates.

What are Software Publisher in X.509 (v3) PKI used for? ✔Correct Answer-They are used to
sign software that will be distributed on the internet, by acting in a strictly informative capacity
to inform the software user that the certificate is signed by a trusted software publishers
certificate authority (CA)

What are Digital Signatures? ✔Correct Answer-They are certificates that hold the 'signature'
of the certificate authority (CA) that verified and issued a digital certificate.

What are the 6 stages of the Key Management Framework? ✔Correct Answer-1. Generation
2. Exchange
3. Storage
4. Rotation
5. Archiving
6. Destruction

What is integrity design? ✔Correct Answer-Assurance that there is no unauthorised
modification of the software or data.

What is a message digest, and what can the recipient do with it? ✔Correct Answer-A message
and a hash value computed by the author of the message:

, > The recipient can compute the hash using the same algorithm as the sender, and then
compare their computed value with the hash value that was provided in the message digest. If
the values match, then the message is unaltered.

What technique ensures a hash digest is protected against the birthday attack? How is this
done? ✔Correct Answer-Salting:
> Adds random bytes when computing the hash, so that the same message hashed by an
attacker will not produce the same digest

Where is hash salting commonly used in applications with users? What type of attack does this
mitigate? ✔Correct Answer-User authentication:
> Mitigates rainbow table and dictionary attacks

What is referential integrity in relation to databases? How does it work? ✔Correct Answer-It
ensures that data is not left in an orphaned state:
> A primary key identifies each row in a table
> Primary keys are referenced as foreign keys in another table

What is resource locking in relation to databases, what is the main risk with misconfiguring it?
✔Correct Answer-When two concurrent operations are not allowed on the same object:
> The main risk is deadlocks and denial of service (DoS)

What is availability design, how is it determined? ✔Correct Answer-Software requirements
that mandate the need for continued business operations:
> Determined with business impact analysis

What does data replication regulate, and what is architecture behind it? ✔Correct Answer-It
ensures that Maximum Tolerable Downtime (MTD) and Recovery Time Objective (RTO) are both
within acceptable levels:
> It uses a primary/secondary node architecture, in which the primary node updates are
propagated to the secondary nodes

What is computing failover? ✔Correct Answer-The automatic switching from an active asset,
to a redundant one

What is the main principle of scalability design? ✔Correct Answer-The ability of software to
handle increasing amounts of work without degradation in functionality or performance.

What is the difference between Vertical (Up) and Horizontal (Out) scaling? ✔Correct Answer--
Vertical adds additional resources to the existing node
- Horizontal means adding additional nodes with the same software on them to the workload

What are the considerations of authentication design? ✔Correct Answer-- MFA & SSO
- Requirements for user experience

Document information

Uploaded on
September 28, 2026
Number of pages
36
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$21.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Studyclub
3.6
(14)
Sold
69
Followers
1
Items
13382
Last sold
6 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions