Questions 1–20: Software Security Foundations & SDL
1. What is the primary goal of the Security Development Lifecycle (SDL)?
A. Increase code reusability
B. Enhance user interface design
C. Reduce vulnerabilities in software development
D. Improve software performance
2. Which phase of SDL involves identifying business requirements and conducting
threat modeling?
A. A1: Security Assessment
B. A2: Architecture
C. A3: Design & Development
D. A5: Ship
3. Which of the following is a deliverable of the Security Assessment (A1) phase?
A. Security test case execution report
B. Product risk profile
C. Architecture threat analysis
D. Final vulnerability scan
4. What does CIA stand for in the context of software security?
A. Confidentiality, Integrity, Availability
B. Control, Investigation, Audit
C. Code, Integrity, Access
D. Configuration, Infrastructure, Analysis
5. What is created during the Architecture (A2) phase to identify data movement and
trust boundaries?
A. Risk matrix
B. Threat vector map
C. Data Flow Diagrams (DFDs)
D. Vulnerability scan
6. Which SDL phase focuses on preparing the application for deployment?
A. A3
B. A4
C. A5
D. PRS
, 7. The SDL Ship phase includes all EXCEPT:
A. Final privacy review
B. Business requirement definition
C. Vulnerability scanning
D. Customer engagement planning
8. Post-Release Support (PRS) includes:
A. Threat modeling
B. Initial architecture risk assessment
C. Third-party security reviews
D. Threat actor profiling
9. The Design & Development (A3) phase includes which of the following?
A. Remediation report
B. Static analysis execution
C. Security test plan creation
D. Software license review
10. What type of test simulates unexpected or random inputs to a system?
A. Penetration testing
B. Static analysis
C. Fuzz testing
D. Threat simulation
11. Which key document tracks all SDL milestones and risk analysis early in a project?
A. Test Plan
B. Threat Profile
C. SDL Project Outline
D. Post-release report
12. What is the main focus of the “secure architecture” practice in OpenSAMM?
A. Preventing phishing
B. Prompting secure-by-default designs
C. Testing performance under load
D. Increasing product features
13. In the PASTA framework, which step involves simulating how threats can exploit
weaknesses?
A. Step 3: Application Decomposition
B. Step 4: Threat Analysis
C. Step 6: Attack Modeling
D. Step 7: Risk Analysis