CSST Exam Preparation: Comprehensive Practice Question Bank
Certified Software Security Tester (CSST) - Advanced Level Practice
Exam
Exam Overview
The Certified Software Security Tester (CSST) certification validates professional knowledge in
identifying, analyzing, and mitigating security vulnerabilities within software applications. The exam
consists of 50 multiple-choice questions with a 70% passing score (35 correct answers), completed
within 60 minutes . This practice question bank covers all major domains including security risks, asset
identification, risk analysis, security policies, auditing, and the security triad .
Section 1: Security Risks and Asset Identification (Questions 1-25)
1. In the context of software security testing, which of the following best defines a "vulnerability"?
A) An action or event that could potentially cause harm to an organization's assets
B) A weakness in a system's design, implementation, or configuration that could be exploited
C) The likelihood that a threat will materialize and cause damage
D) A measure of the potential financial loss from a security incident
Correct Answer: B
Rationale: A vulnerability is a specific weakness or flaw in a system's security posture that can potentially
be exploited by threats. This is distinct from a threat (option A), which is a potential cause of harm; risk
(option C), which considers likelihood; and impact (option D), which focuses on consequences.
2. Which of the following represents the correct order of the risk management process?
A) Risk identification → Risk analysis → Risk evaluation → Risk treatment
B) Risk analysis → Risk identification → Risk treatment → Risk evaluation
C) Risk evaluation → Risk identification → Risk analysis → Risk treatment
D) Risk treatment → Risk evaluation → Risk identification → Risk analysis
,Correct Answer: A
Rationale: The proper sequence is risk identification (finding risks), risk analysis (understanding nature
and impact), risk evaluation (comparing against criteria), and risk treatment (implementing controls).
This systematic approach ensures comprehensive risk management .
3. What type of asset includes customer databases, trade secrets, and intellectual property?
A) Tangible assets
B) Intangible assets
C) Physical assets
D) Operational assets
Correct Answer: B
Rationale: Intangible assets are non-physical assets that have value, including information assets like
databases, proprietary information, and intellectual property. Tangible assets (option A) are physical
items, while physical assets (option C) specifically refer to hardware and facilities .
4. In security risk assessment, what is the primary purpose of asset identification?
A) To determine the monetary value of all company property
B) To catalog and prioritize resources that need protection
C) To comply with regulatory reporting requirements
D) To create an inventory for insurance purposes
Correct Answer: B
Rationale: Asset identification serves to systematically catalog resources that require protection and
prioritize them based on their importance to the organization. This enables effective allocation of security
resources and controls .
5. Which type of security risk involves unauthorized access to data or systems?
A) Confidentiality risk
B) Integrity risk
C) Availability risk
D) Authentication risk
,Correct Answer: A
Rationale: Confidentiality risks specifically involve unauthorized access to or exposure of sensitive
information. Integrity risks (option B) involve unauthorized modification, availability risks (option C)
involve denial of service, and authentication risks relate to identity verification failures .
6. Which of the following is NOT a component of the security triad (CIA)?
A) Confidentiality
B) Integrity
C) Authorization
D) Availability
Correct Answer: C
Rationale: The security triad consists of Confidentiality, Integrity, and Availability (CIA). Authorization
(option C) is related to access control but is not one of the three core pillars of information security .
7. In the context of security testing, what does the term "threat vector" describe?
A) The path or means by which an attacker gains access to a system
B) The total number of potential attackers targeting a system
C) A measure of the system's vulnerability to attacks
D) The encryption algorithm used to protect data
Correct Answer: A
Rationale: A threat vector is the specific path or methodology an attacker uses to gain unauthorized
access to a system. This includes attack surfaces like email attachments, vulnerable web applications, or
social engineering techniques .
8. Which of the following represents a qualitative risk assessment approach?
A) Calculating potential financial losses in dollars
B) Assigning risk ratings such as "High," "Medium," or "Low"
C) Determining the exact probability of risk occurrence
D) Computing annualized loss expectancy (ALE)
, Correct Answer: B
Rationale: Qualitative risk assessment uses descriptive categories to evaluate risk rather than numerical
values. Options A, C, and D (calculating financial losses, exact probabilities, and ALE) are all elements of
quantitative risk assessment .
9. What is the primary characteristic of an "advanced persistent threat" (APT)?
A) It uses only automated scanning tools
B) It is a single, isolated attack event
C) It is a prolonged, targeted attack with significant resources
D) It focuses exclusively on denial-of-service attacks
Correct Answer: C
Rationale: APTs are sophisticated, sustained attacks where threat actors maintain long-term access to a
target network. They are characterized by being well-resourced, targeted, and persistent, unlike single-
event attacks .
10. Which risk treatment strategy transfers the risk to a third party?
A) Risk avoidance
B) Risk mitigation
C) Risk acceptance
D) Risk transference
Correct Answer: D
Rationale: Risk transference shifts the financial or operational impact of a risk to another entity, such as
purchasing cyber insurance or outsourcing operations to a managed security provider. Avoidance (A)
eliminates the risk, mitigation (B) reduces it, and acceptance (C) acknowledges it without action .
11. In software security, what does the term "attack surface" refer to?
A) The total number of security patches applied
B) The sum of all points where an unauthorized user can enter a system
C) The physical location where servers are housed
D) The number of employees with system access
Certified Software Security Tester (CSST) - Advanced Level Practice
Exam
Exam Overview
The Certified Software Security Tester (CSST) certification validates professional knowledge in
identifying, analyzing, and mitigating security vulnerabilities within software applications. The exam
consists of 50 multiple-choice questions with a 70% passing score (35 correct answers), completed
within 60 minutes . This practice question bank covers all major domains including security risks, asset
identification, risk analysis, security policies, auditing, and the security triad .
Section 1: Security Risks and Asset Identification (Questions 1-25)
1. In the context of software security testing, which of the following best defines a "vulnerability"?
A) An action or event that could potentially cause harm to an organization's assets
B) A weakness in a system's design, implementation, or configuration that could be exploited
C) The likelihood that a threat will materialize and cause damage
D) A measure of the potential financial loss from a security incident
Correct Answer: B
Rationale: A vulnerability is a specific weakness or flaw in a system's security posture that can potentially
be exploited by threats. This is distinct from a threat (option A), which is a potential cause of harm; risk
(option C), which considers likelihood; and impact (option D), which focuses on consequences.
2. Which of the following represents the correct order of the risk management process?
A) Risk identification → Risk analysis → Risk evaluation → Risk treatment
B) Risk analysis → Risk identification → Risk treatment → Risk evaluation
C) Risk evaluation → Risk identification → Risk analysis → Risk treatment
D) Risk treatment → Risk evaluation → Risk identification → Risk analysis
,Correct Answer: A
Rationale: The proper sequence is risk identification (finding risks), risk analysis (understanding nature
and impact), risk evaluation (comparing against criteria), and risk treatment (implementing controls).
This systematic approach ensures comprehensive risk management .
3. What type of asset includes customer databases, trade secrets, and intellectual property?
A) Tangible assets
B) Intangible assets
C) Physical assets
D) Operational assets
Correct Answer: B
Rationale: Intangible assets are non-physical assets that have value, including information assets like
databases, proprietary information, and intellectual property. Tangible assets (option A) are physical
items, while physical assets (option C) specifically refer to hardware and facilities .
4. In security risk assessment, what is the primary purpose of asset identification?
A) To determine the monetary value of all company property
B) To catalog and prioritize resources that need protection
C) To comply with regulatory reporting requirements
D) To create an inventory for insurance purposes
Correct Answer: B
Rationale: Asset identification serves to systematically catalog resources that require protection and
prioritize them based on their importance to the organization. This enables effective allocation of security
resources and controls .
5. Which type of security risk involves unauthorized access to data or systems?
A) Confidentiality risk
B) Integrity risk
C) Availability risk
D) Authentication risk
,Correct Answer: A
Rationale: Confidentiality risks specifically involve unauthorized access to or exposure of sensitive
information. Integrity risks (option B) involve unauthorized modification, availability risks (option C)
involve denial of service, and authentication risks relate to identity verification failures .
6. Which of the following is NOT a component of the security triad (CIA)?
A) Confidentiality
B) Integrity
C) Authorization
D) Availability
Correct Answer: C
Rationale: The security triad consists of Confidentiality, Integrity, and Availability (CIA). Authorization
(option C) is related to access control but is not one of the three core pillars of information security .
7. In the context of security testing, what does the term "threat vector" describe?
A) The path or means by which an attacker gains access to a system
B) The total number of potential attackers targeting a system
C) A measure of the system's vulnerability to attacks
D) The encryption algorithm used to protect data
Correct Answer: A
Rationale: A threat vector is the specific path or methodology an attacker uses to gain unauthorized
access to a system. This includes attack surfaces like email attachments, vulnerable web applications, or
social engineering techniques .
8. Which of the following represents a qualitative risk assessment approach?
A) Calculating potential financial losses in dollars
B) Assigning risk ratings such as "High," "Medium," or "Low"
C) Determining the exact probability of risk occurrence
D) Computing annualized loss expectancy (ALE)
, Correct Answer: B
Rationale: Qualitative risk assessment uses descriptive categories to evaluate risk rather than numerical
values. Options A, C, and D (calculating financial losses, exact probabilities, and ALE) are all elements of
quantitative risk assessment .
9. What is the primary characteristic of an "advanced persistent threat" (APT)?
A) It uses only automated scanning tools
B) It is a single, isolated attack event
C) It is a prolonged, targeted attack with significant resources
D) It focuses exclusively on denial-of-service attacks
Correct Answer: C
Rationale: APTs are sophisticated, sustained attacks where threat actors maintain long-term access to a
target network. They are characterized by being well-resourced, targeted, and persistent, unlike single-
event attacks .
10. Which risk treatment strategy transfers the risk to a third party?
A) Risk avoidance
B) Risk mitigation
C) Risk acceptance
D) Risk transference
Correct Answer: D
Rationale: Risk transference shifts the financial or operational impact of a risk to another entity, such as
purchasing cyber insurance or outsourcing operations to a managed security provider. Avoidance (A)
eliminates the risk, mitigation (B) reduces it, and acceptance (C) acknowledges it without action .
11. In software security, what does the term "attack surface" refer to?
A) The total number of security patches applied
B) The sum of all points where an unauthorized user can enter a system
C) The physical location where servers are housed
D) The number of employees with system access