100% VERIFIED CORRECT ANSWERS
1. What is the study of real-world software security initiatives organized so
companies can measure their initiatives and understand how to evolve them
over time?
A. Security features and design
B. ISO 27001
C. Building Security in Maturity Model (BSIMM)
D. OWASP Software Assurance Maturity Model (SAMM)
Correct Answer: C - Building Security in Maturity Model (BSIMM)
Explanation: BSIMM is specifically designed to study real-world software security
initiatives and help organizations measure and evolve their security practices over
time.
2. What is the analysis of computer software that is performed without
executing programs?
A. Fuzzing
B. Dynamic analysis
C. OWASP ZAP
D. Static analysis
Correct Answer: D - Static analysis
Explanation: Static analysis examines source code, bytecode, or binary code
without executing the program, identifying potential vulnerabilities through code
review and automated tools.
,3. Which secure coding best practice says to use parameterized queries,
encrypted connection strings stored in separate configuration files, and strong
passwords or multi-factor authentication?
A. File management
B. Access control
C. Session management
D. Database security
Correct Answer: D - Database security
Explanation: These practices specifically relate to protecting database interactions
and credentials, which fall under the database security best practice category.
4. Which secure coding best practice says that all information passed to other
systems should be encrypted?
A. Output encoding
B. Database security
C. Communication security
D. Memory management
Correct Answer: C - Communication security
Explanation: Encrypting information passed between systems is a fundamental
communication security practice to prevent eavesdropping and data interception.
5. A company is preparing to add a new feature to its flagship software product.
The new feature is similar to features that have been added in previous years,
and the requirements are well-documented. The project is expected to last three
to four months, at which time the new feature will be released to customers.
Project team members will focus solely on the new feature until the project
ends. Which software development methodology is being used?
A. Scrum
B. Extreme programming
,C. Agile
D. Waterfall
Correct Answer: D - Waterfall
Explanation: The linear, sequential approach with well-documented requirements,
fixed timeline, and dedicated team focus until completion characterizes the
Waterfall methodology.
6. A new product will require an administration section for a small number of
users. Normal users will be able to view limited customer information and
should not see admin functionality within the application. Which concept is
being used?
A. Software security champion
B. Elevation of privilege
C. Privacy
D. POLP (Principle of Least Privilege)
Correct Answer: D - POLP
Explanation: The Principle of Least Privilege ensures users only have the minimum
access needed for their role, which is demonstrated by restricting admin
functionality from normal users.
7. The software security team is currently working to identify approaches for
input validation, authentication, authorization, and configuration management
of a new software product so they can deliver a security profile. Which threat
modeling step is being described?
A. Drawing data flow diagram
B. Rating threats
C. Analyzing the target
D. Identifying and documenting threats
Correct Answer: C - Analyzing the target
Explanation: Analyzing the target involves identifying security requirements and
, approaches for various security controls like input validation, authentication, and
authorization.
8. The scrum team is attending their morning meeting, which is scheduled at the
beginning of the work day. Each team member reports what they accomplished
yesterday, what they plan to accomplish today, and if they have any
impediments that may cause them to miss their delivery deadline. Which scrum
ceremony is the team participating in?
A. Sprint planning
B. Sprint review
C. Sprint retrospective
D. Daily scrum
Correct Answer: D - Daily scrum
Explanation: The daily scrum (stand-up) is a short daily meeting where team
members synchronize activities and report progress, plans, and impediments.
9. Which security control prevents attackers from injecting malicious code by
ensuring that all user input is properly validated before processing?
A. Output encoding
B. Input validation
C. Session management
D. Error handling
Correct Answer: B - Input validation
Explanation: Input validation is the primary defense against injection attacks by
checking and sanitizing user-supplied data before it is processed by the
application.
10. What type of testing involves providing invalid, unexpected, or random data
as inputs to a computer program?