1|Page
CSSLP TEST FINAL EXAM ACTUAL EXAM AND
PRACTICE QUESTIONS EXAM COMPLETE
ACCURATE EXAM QUESTIONS WITH DETAILED
VERIFIED ANSWERS (100% CORRECT ANSWERS)
/ALREADY GRADED A+/ LATEST EXAM!!!
QUESTION 1
An organization has signed a contract to build a large
Information System (IS) for the United States government.
Which framework, guideline, or standard would BEST
meet government information processing requirements?
A. Control Objectives for Information and Related
Technology (COBIT)
B. Information Technology Infrastructure Library (ITIL)
C. National Institute of Standards and Technology (NIST)
D. International Organization for Standardization (ISO)
27000 - Answer-Correct Answer: C
Explanation/Reference:
NIST Special Publication 800-171 is rapidly emerging as
the benchmark used by the civilian US government and
Department of Defense for evaluating the security and
,2|Page
privacy posture of nonfederal organizations that seek to
contract with the US government.
QUESTION 2
An organization deploys an Internet web application. A
security researcher sends an e-mail to a mailing list stating
that the web application is susceptible to Cross-Site
Scripting (XSS)
What type of testing could BEST discover this type of
vulnerability?
A. Simulation testing
B. Automated regression testing
C. Fuzz testing
D. Integration testing - Answer-Correct Answer: C
Explanation/Reference:
Intellifuzz is a Python script designed to not only
determine if a cross-site scripting attack is possible, but
also determine the exact payload needed to cleanly break
out of the code. Many web scanners and fuzzers operate
by using a long list of possible payloads and recording the
response to see if the payload is reflected. However, just
,3|Page
because a payload is reflected does not mean it will
execute. For example, if the payload is reflected as an
HTML attribute, a carefully crafted string must be created
to first break out of the attribute using quotes, then
potentially break out of the tag, then finally launch the
script. Intellifuzz aims to take care of crafting the payload
for you by first detecting the location of the parameter
reflection, then using a number of tests to determine what
characters are needed to cause a successful execution.
QUESTION 3
Which of the following mitigates cryptographic keys from
being stoles by cold-boot attacks?
A. Use symmetric keys instead of asymmetric keys
B. Overwrite the keys in memory once they are no longer
needed
C. Use passwords to derive the cryptographic keys
D. Combine cryptographic keys with random salt values -
Answer-Correct Answer: B
Explanation/Reference:
After a computer is powered off, the data in RAM
disappears rapidly, but it can remain in RAM up to several
, 4|Page
minutes after shutdown. An attacker having access to a
computer before it disappears completely could recover
important data from your session. This can be achieved
using a technique called cold boot attack . To prevent this
attack, the data in RAM is overwritten by random data
when shutting down. This erases all traces from your
session on that computer.
QUESTION 4
A strong application architecture that provides separation
and security between components is essential for
preventing which of the following?
A. Security misconfiguration
B. Cross-Site Scripting (XSS) attacks
C. Tampering with source code modules
D. Security breaches due to weak cryptographic
algorithms - Answer-Correct Answer: A
Explanation/Reference:
Security misconfiguration can happen at any level of an
application stack, including the platform, web server,
application server, database, framework, and custom
CSSLP TEST FINAL EXAM ACTUAL EXAM AND
PRACTICE QUESTIONS EXAM COMPLETE
ACCURATE EXAM QUESTIONS WITH DETAILED
VERIFIED ANSWERS (100% CORRECT ANSWERS)
/ALREADY GRADED A+/ LATEST EXAM!!!
QUESTION 1
An organization has signed a contract to build a large
Information System (IS) for the United States government.
Which framework, guideline, or standard would BEST
meet government information processing requirements?
A. Control Objectives for Information and Related
Technology (COBIT)
B. Information Technology Infrastructure Library (ITIL)
C. National Institute of Standards and Technology (NIST)
D. International Organization for Standardization (ISO)
27000 - Answer-Correct Answer: C
Explanation/Reference:
NIST Special Publication 800-171 is rapidly emerging as
the benchmark used by the civilian US government and
Department of Defense for evaluating the security and
,2|Page
privacy posture of nonfederal organizations that seek to
contract with the US government.
QUESTION 2
An organization deploys an Internet web application. A
security researcher sends an e-mail to a mailing list stating
that the web application is susceptible to Cross-Site
Scripting (XSS)
What type of testing could BEST discover this type of
vulnerability?
A. Simulation testing
B. Automated regression testing
C. Fuzz testing
D. Integration testing - Answer-Correct Answer: C
Explanation/Reference:
Intellifuzz is a Python script designed to not only
determine if a cross-site scripting attack is possible, but
also determine the exact payload needed to cleanly break
out of the code. Many web scanners and fuzzers operate
by using a long list of possible payloads and recording the
response to see if the payload is reflected. However, just
,3|Page
because a payload is reflected does not mean it will
execute. For example, if the payload is reflected as an
HTML attribute, a carefully crafted string must be created
to first break out of the attribute using quotes, then
potentially break out of the tag, then finally launch the
script. Intellifuzz aims to take care of crafting the payload
for you by first detecting the location of the parameter
reflection, then using a number of tests to determine what
characters are needed to cause a successful execution.
QUESTION 3
Which of the following mitigates cryptographic keys from
being stoles by cold-boot attacks?
A. Use symmetric keys instead of asymmetric keys
B. Overwrite the keys in memory once they are no longer
needed
C. Use passwords to derive the cryptographic keys
D. Combine cryptographic keys with random salt values -
Answer-Correct Answer: B
Explanation/Reference:
After a computer is powered off, the data in RAM
disappears rapidly, but it can remain in RAM up to several
, 4|Page
minutes after shutdown. An attacker having access to a
computer before it disappears completely could recover
important data from your session. This can be achieved
using a technique called cold boot attack . To prevent this
attack, the data in RAM is overwritten by random data
when shutting down. This erases all traces from your
session on that computer.
QUESTION 4
A strong application architecture that provides separation
and security between components is essential for
preventing which of the following?
A. Security misconfiguration
B. Cross-Site Scripting (XSS) attacks
C. Tampering with source code modules
D. Security breaches due to weak cryptographic
algorithms - Answer-Correct Answer: A
Explanation/Reference:
Security misconfiguration can happen at any level of an
application stack, including the platform, web server,
application server, database, framework, and custom