Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 86 pages
Exam (elaborations)

CSSLP DOMAIN1,2,3,4 &5 - SECURE SOFTWARE TESTING QUESTIONS AND ANSWERS (VERIFIED AND WELL DETAILED ANSWERS) LATEST UPDATE 2024/2025

Document preview thumbnail
Preview 4 out of 86 pages

CSSLP DOMAIN1,2,3,4 &5 - SECURE SOFTWARE TESTING QUESTIONS AND ANSWERS (VERIFIED AND WELL DETAILED ANSWERS) LATEST UPDATE 2024/2025

Content preview

CSSLP DOMAIN1,2,3,4 &5 - SECURE SOFTWARE
TESTING QUESTIONS AND ANSWERS (VERIFIED AND
WELL DETAILED ANSWERS) LATEST UPDATE
2024/2025



The PRIMARY reason for incorporating security into the software
development life cycle is to protect
A. the unauthorized disclosure of information.
B. the corporate brand and reputation.
C. against hackers who intend to misuse the software.
D. the developers from releasing software with security defects. -
CORRECT ANSWER B. the corporate brand and reputation


The resiliency of software to withstand attacks that attempt to modify or
alter data in an unauthorized manner is referred to as
A. Confidentiality
B. Integrity
C. Availability
D. Authorization - CORRECT ANSWER B. integrity


The MAIN reason as to why the availability aspects of software must be
part of the organization's software security initiatives is:
A. software issues can cause downtime to the business
B. developers need to be trained in the business continuity procedures.

,C. testing for availability of the software and data is often ignored.
D. hackers like to conduct Denial of Service (DoS) attacks against the
organization - CORRECT ANSWER A. software issues can cause
downtime to the business


Developing the software to monitor its functionality and report when the
software is down and unable to provide the expected service to the
business is a protection to assure which of the following?
A. Confidentiality
B. Integrity
C. Availability
D. Authentication - CORRECT ANSWER C. Availability


When a customer attempts to log into their bank account, the customer is
required to enter a nonce from the token device that was issued to the
customer by the bank. This type of authentication is also known as
which of the following?
A. Ownership based authentication
B. Two factor authentication
C. Characteristic based authentication
D. Knowledge based authentication. - CORRECT ANSWER A.
Ownership based authentication


Multi-factor authentication is most closely related to which of the
following security design principles?
A. Separation of Duties

,B. Defense in depth
C. Complete mediation
D. Open design - CORRECT ANSWER B. Defense in depth


Audit logs can be used for all of the following EXCEPT
A. providing evidentiary information
B. assuring that the user cannot deny their actions
C. detecting the actions that were undertaken
D. preventing a user from performing some unauthorized operations -
CORRECT ANSWER D. preventing a user from performing some
unauthorized operations


Organizations often pre-determine the acceptable number of user errors
before recording them as security violations. This number is otherwise
known as
A. Clipping level
B. Known Error
C. Minimum Security Baseline
D. Maximum Tolerable Downtime - CORRECT ANSWER A. Clipping
Level


A security principle that maintains the confidentiality, integrity and
availability of the software and data, besides allowing for rapid recovery
to the state of normal operations, when unexpected events occur is the
security design principle of

, A. defense in depth
B. economy of mechanisms
C. fail secure
D. psychological acceptability - CORRECT ANSWER C. fail secure


Requiring the end user to accept an 'AS-IS' disclaimer clause before
installation of your software is an example of risk
A. avoidance
B. mitigation
C. transference
D acceptance - CORRECT ANSWER C. transference


An instrument that is used to communicate and mandate organizational
and management goals and objectives at a high level is a
A. standard
B. policy
C. baseline
D. guideline - CORRECT ANSWER B. policy


The Systems Security Engineering Capability Maturity Model
(SSECMM) is an international recognized standard that publishes
guidelines to
A. provide metrics for measuring the software and its behavior, and
using the software in a specific context of use

Document information

Uploaded on
December 18, 2024
Number of pages
86
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$23.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
tutorlorghon
4.7
(253)
Sold
773
Followers
18
Items
6455
Last sold
2 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions