D487 Practice Question with 100% Verified
Answers
software security
______ is about building secure software: designing software tobe secure; making sure that
software is secure; and educating software developers, architects, and users about how to
build security in
Application security
_____is about protecting software and the systems that software runs in a post-facto, only
after development is complete
Security Development Lifecycle
__is a software development process used to reduce software maintenance costs and increase
reliability of software concerning software security related bugs.
1- To reduce the number of security vulnerabilities and privacy problems
2-to reduce the severity of the vulnerabilities that remain
2 goals of SDL
Taint Analysis
Static analysis tools use a technique called "________________" to look for unfiltered or
unsanitized inputs (the scourge of software security) in application code
Confidentiality, integrity, and availability
There are three minimum goals that that the information security industry considers of
primary importance for an SDL
information security
,The protection of information and information systems from unauthorized access, use,
disclosure, disruption, modification, or destruction in order to provide confidentiality,
integrity, and availability
Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for
protecting personal privacy and proprietary information
Integrity
Guarding against improper information modification or destruction, and includes ensuring
information non-repudiation and authenticity.
Availability
Ensuring timely and reliable access to and use of information
attack surface
the entry points and exit points of an application that may be accessible to an attacker
BSIMM
____ is the study of real-world software security initiatives organized so that you can
determine where you stand withyour software security initiative and how to evolve your
efforts over time
OWASP software assurance maturity model
is a flexible and prescriptive framework for building security into a software development
organization
ISO/IEC 27001
, It is an information security management system (ISMS) standard that specifies a
management system intended to bring information security under formal management control
ISO/IEC 27034
standard provides guidance to help organizations embed security within their processes that
help secure applications running in the environment, including application life cycle
processes
Software Assurance Forum for Excellence in Code (SAFE)
_____is a nonprofit organization dedicated to increasing trust in information and
communications technology products and services through the advancement of effective
software assurance method
NIST Software Assurance Metrics and Tool Evaluation (SAMATE)
_____project is dedicated to improving software assurance by developing methods to enable
software tool
evaluations, measuring the effectiveness of tools and techniques, and identifying gaps in
tools and methods
National Vulnerability Database (NVD)
_____is the U.S. government repository of
standards-based vulnerability management data represented using the Security Content
Automation Protocol (SCAP)
Common Computer Vulnerabilities and Exposures (CVE)
Answers
software security
______ is about building secure software: designing software tobe secure; making sure that
software is secure; and educating software developers, architects, and users about how to
build security in
Application security
_____is about protecting software and the systems that software runs in a post-facto, only
after development is complete
Security Development Lifecycle
__is a software development process used to reduce software maintenance costs and increase
reliability of software concerning software security related bugs.
1- To reduce the number of security vulnerabilities and privacy problems
2-to reduce the severity of the vulnerabilities that remain
2 goals of SDL
Taint Analysis
Static analysis tools use a technique called "________________" to look for unfiltered or
unsanitized inputs (the scourge of software security) in application code
Confidentiality, integrity, and availability
There are three minimum goals that that the information security industry considers of
primary importance for an SDL
information security
,The protection of information and information systems from unauthorized access, use,
disclosure, disruption, modification, or destruction in order to provide confidentiality,
integrity, and availability
Confidentiality
Preserving authorized restrictions on information access and disclosure, including means for
protecting personal privacy and proprietary information
Integrity
Guarding against improper information modification or destruction, and includes ensuring
information non-repudiation and authenticity.
Availability
Ensuring timely and reliable access to and use of information
attack surface
the entry points and exit points of an application that may be accessible to an attacker
BSIMM
____ is the study of real-world software security initiatives organized so that you can
determine where you stand withyour software security initiative and how to evolve your
efforts over time
OWASP software assurance maturity model
is a flexible and prescriptive framework for building security into a software development
organization
ISO/IEC 27001
, It is an information security management system (ISMS) standard that specifies a
management system intended to bring information security under formal management control
ISO/IEC 27034
standard provides guidance to help organizations embed security within their processes that
help secure applications running in the environment, including application life cycle
processes
Software Assurance Forum for Excellence in Code (SAFE)
_____is a nonprofit organization dedicated to increasing trust in information and
communications technology products and services through the advancement of effective
software assurance method
NIST Software Assurance Metrics and Tool Evaluation (SAMATE)
_____project is dedicated to improving software assurance by developing methods to enable
software tool
evaluations, measuring the effectiveness of tools and techniques, and identifying gaps in
tools and methods
National Vulnerability Database (NVD)
_____is the U.S. government repository of
standards-based vulnerability management data represented using the Security Content
Automation Protocol (SCAP)
Common Computer Vulnerabilities and Exposures (CVE)