Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 54 pages
Exam (elaborations)

CSST Exam Preparation: Advanced Certified Software Security Tester (CSST) - Comprehensive Practice Examination

Document preview thumbnail
Preview 4 out of 54 pages

CSST Exam Preparation: Advanced Certified Software Security Tester (CSST) - Comprehensive Practice Examination

Content preview

CSST Exam Preparation: Advanced Certified
Software Security Tester (CSST) - Comprehensive
Practice Examination

Examination Overview
Certification: Certified Software Security Tester (CSST)
Level: Advanced / Expert
Target Audience: Security Professionals, Penetration Testers, Security Architects,
DevSecOps Engineers, and Senior QA Engineers specializing in Application Security
Total Questions: 150 Multiple-Choice Questions
Recommended Time: 180 Minutes (3 Hours)
Passing Score: 70% (105 Correct Answers)
Domain Coverage: Security Risk Management (25%), Asset Identification &
Classification (15%), Security Policies & Governance (20%), Security Auditing &
Assessment (20%), Testing Methodologies (10%), Information Assurance &
Organizational Context (10%)




Domain 1: Advanced Security Risk Management and
Threat Analysis (Questions 1-35)
1. In the context of Advanced Persistent Threats (APTs), which of the following
characteristics most accurately distinguishes them from standard cyber attacks?

A) They exclusively target financial institutions and use only zero-day exploits
B) They are characterized by prolonged, targeted operations with significant
resources and sophisticated techniques
C) They rely solely on social engineering tactics without technical exploitation
D) They are typically conducted by script kiddies using automated tools

Correct Answer: B
Rationale: APTs are distinguished by their sophisticated, sustained nature where threat

,actors maintain long-term access using advanced techniques. They are well-resourced,
targeted, and persistent, unlike single-event attacks conducted by less sophisticated
actors.

2. Which of the following represents the MOST comprehensive risk assessment
approach when evaluating a complex distributed system?

A) Performing a quantitative risk analysis using Annualized Loss Expectancy (ALE)
calculations
B) Conducting a qualitative risk assessment with stakeholder interviews
C) Implementing a hybrid approach combining quantitative metrics with
qualitative expert judgment
D) Relying solely on automated vulnerability scanning results

Correct Answer: C
Rationale: Complex distributed systems require a hybrid approach that combines the
numerical precision of quantitative analysis with the contextual insights of qualitative
assessment. This provides a more comprehensive understanding of risks in
multifaceted environments where pure quantitative or qualitative approaches alone
are insufficient.

3. The concept of "risk aggregation" in enterprise security testing refers to:

A) Adding individual risk scores to calculate total organizational risk
B) The process of combining and correlating risks across different business units
and systems
C) Multiplying risk probabilities by impacts for each asset
D) The practice of ignoring low-level risks in favor of high-level ones

Correct Answer: B
Rationale: Risk aggregation involves combining and correlating risks across an
organization to understand cumulative exposure. Individual risks can interact and
compound, creating systemic risk that exceeds the sum of individual risk scores.

4. When performing a threat modeling exercise using the STRIDE methodology,
which threat category addresses the scenario where an attacker modifies data in
transit?

, A) Spoofing
B) Tampering
C) Repudiation
D) Information Disclosure

Correct Answer: B
Rationale: STRIDE categorizes tampering as unauthorized modification of data. This
includes data modification in transit, at rest, or during processing. Tampering attacks
compromise data integrity.

5. In the DREAD risk assessment model, the "Discoverability" component
primarily evaluates:

A) How easy it is for attackers to find the vulnerability
B) How much damage the vulnerability could cause
C) How many users are affected by the vulnerability
D) How easy it is to exploit the vulnerability

Correct Answer: A
Rationale: In the DREAD model, Discoverability measures how easy it is for an attacker
to identify and find the vulnerability. This factor is particularly important because even
severe vulnerabilities that are difficult to discover may pose lower overall risk than
easily found ones.

6. What is the primary limitation of using Common Vulnerability Scoring System
(CVSS) v3.1 scores in isolation for risk prioritization?

A) CVSS scores are too difficult to calculate accurately
B) CVSS does not account for organizational context and business impact
C) CVSS only applies to network vulnerabilities
D) CVSS scores cannot be compared across different vulnerability types

Correct Answer: B
Rationale: CVSS provides a standardized severity score based on technical
characteristics, but it does not incorporate organizational context such as asset
criticality, business impact, or existing compensating controls. Organizations must
supplement CVSS with contextual risk factors.

, 7. Which of the following best describes the relationship between threat
intelligence and security testing?

A) Threat intelligence replaces the need for security testing
B) Threat intelligence informs testing priorities by identifying current attack
patterns and techniques
C) Threat intelligence is only useful after a security breach occurs
D) Threat intelligence and security testing are unrelated activities

Correct Answer: B
Rationale: Threat intelligence provides actionable information about current threats,
attack patterns, and adversary techniques, which helps security testers focus on the
most relevant and current attack vectors during testing.

8. In Bayesian risk analysis, the posterior probability of a security incident is
calculated by:

A) Multiplying prior probability by likelihood of evidence
B) Dividing prior probability by the likelihood of evidence
C) Combining prior probability with new evidence using Bayes' theorem
D) Calculating the absolute frequency of incidents

Correct Answer: C
Rationale: Bayesian risk analysis updates prior probabilities with new evidence using
Bayes' theorem to calculate posterior probabilities. This approach allows for dynamic
risk assessment as new threat intelligence and security events emerge.

9. The "Confidentiality, Integrity, and Availability" (CIA) triad, when applied to risk
assessment, requires that:

A) All three components must always be equally prioritized
B) The relative importance of each component varies based on business
requirements and data classification
C) Availability is always the most critical component
D) Confidentiality always takes precedence over other components

Document information

Uploaded on
July 1, 2026
Number of pages
54
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2980
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions