1
D487 Questions with Correct Answers
for Specific Exam Mail
What is the study of real-world software security initiatives
organized so companies can measure their initiatives and
understand how to evolve them over time?
-Building Security in Maturity Model (BSIMM)
-Security features and design
-OWASP Software Assurance Maturity Model (SAMM)
-ISO 27001
Ans: -Building Security in Maturity Model (BSIMM)
What is the analysis of computer software that is
performed without executing programs?
-static analysis
-fuzzing
-dynamic analysis
-owasp zap
:
vPretest - Stuvia US
,2
Ans: -static analysis
what iso standard is the benchmark for information
security today?
-iso 27001
-iso 7799
-iso 27034
-iso 8601
Ans: -iso 27001
what is the analysis of computer software that is
performed by executing programs on a real or virtual
processor in real time?
-dynamic analysis
-static analysis
-fuzzing
-security testing
Ans: -dynamic analysis
:
vPretest - Stuvia US
,3
which person is responsible for designing, planning, and
implementing secure coding practices and security
testing methodologies?
-software security architect
-product security developer
-software security champion
-software tester
Ans: -software security architect
what is a list of information security vulnerabilities that
aims to provide names for publicly known problems?
-common computer vulnerabilities and exposures (CVE)
- SANS institute top cyber security risks
-bugtraq
- Carnegie melon computer emergency readiness team
(CERT)
Ans: -common computer vulnerabilities and exposures
(CVE)
:
vPretest - Stuvia US
, 4
which secure coding best practice uses well-tested,
publicly available algorithms to hide product data from
unauthorized access?
-access control
-authentication and password management
-cryptographic practices
-data protection
Ans: -cryptographic practices
which secure coding best practice ensures servers,
frameworks, and system components are all running the
latest approved versions?
-file management
-input validation
-database security
-system configuration
Ans: -system configuration
:
vPretest - Stuvia US
D487 Questions with Correct Answers
for Specific Exam Mail
What is the study of real-world software security initiatives
organized so companies can measure their initiatives and
understand how to evolve them over time?
-Building Security in Maturity Model (BSIMM)
-Security features and design
-OWASP Software Assurance Maturity Model (SAMM)
-ISO 27001
Ans: -Building Security in Maturity Model (BSIMM)
What is the analysis of computer software that is
performed without executing programs?
-static analysis
-fuzzing
-dynamic analysis
-owasp zap
:
vPretest - Stuvia US
,2
Ans: -static analysis
what iso standard is the benchmark for information
security today?
-iso 27001
-iso 7799
-iso 27034
-iso 8601
Ans: -iso 27001
what is the analysis of computer software that is
performed by executing programs on a real or virtual
processor in real time?
-dynamic analysis
-static analysis
-fuzzing
-security testing
Ans: -dynamic analysis
:
vPretest - Stuvia US
,3
which person is responsible for designing, planning, and
implementing secure coding practices and security
testing methodologies?
-software security architect
-product security developer
-software security champion
-software tester
Ans: -software security architect
what is a list of information security vulnerabilities that
aims to provide names for publicly known problems?
-common computer vulnerabilities and exposures (CVE)
- SANS institute top cyber security risks
-bugtraq
- Carnegie melon computer emergency readiness team
(CERT)
Ans: -common computer vulnerabilities and exposures
(CVE)
:
vPretest - Stuvia US
, 4
which secure coding best practice uses well-tested,
publicly available algorithms to hide product data from
unauthorized access?
-access control
-authentication and password management
-cryptographic practices
-data protection
Ans: -cryptographic practices
which secure coding best practice ensures servers,
frameworks, and system components are all running the
latest approved versions?
-file management
-input validation
-database security
-system configuration
Ans: -system configuration
:
vPretest - Stuvia US