CSSLP Exam Questions with all Correct & 100% Verified
Answers |Actual Complete Update |Already Graded A+
(Just Released)
Which of the following processes culminates in an agreement between key players that a
system in its current configuration and operation provides adequate protection controls?
a. Information Assurance (IA)
b. Information Systems Security Engineering (ISSE)
c. Certification & Accreditation (C&A)
d. Risk Management ✔Correct Answer-c
Which of the following cryptographic system services ensures that information will not be
disclosed to any unauthorized person on a local network?
a. Authentication
b. Integrity
c. Non-repudiation
d. Confidentiality ✔Correct Answer-d
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a
methodology for assessing the security of information systems. Which of the following FITSAF
levels shows that the procedures and controls have been implemented?
a. Level 2
b. Level 3
c. Level 5
d. Level 1
e. Level 4 ✔Correct Answer-b
In which of the following test methodologies do assessors use all available documentation and
work under no constraints, and attempt to circumvent the security features of an information
system?
a. Full operational test
b. Penetration test
c. Paper-test
d. Walk-through test ✔Correct Answer-b
Which of the following rated systems of the Orange Book has mandatory protection of the TCB?
,a. A-rated
b. B-rated
c. D-rated
d. C-rated ✔Correct Answer-b
Drop the appropriate value to complete the formula.
Single loss expectancy = Asset value ($) x ___________
a. Exposure Factor (EF)
b. Annual Loss Expectancy (ALE)
c. Annualized Rate of Occurrence (ARO) ✔Correct Answer-a
FIPS 199 defines the three levels of potential impact on organizations. Which of the following
potential impact levels shows limited adverse affects on organizational operations,
organizational assets, or individuals?
a. Moderate
b. Low
c. Medium
d. High ✔Correct Answer-b
Which of the following life cycle model activities establishes service relationships and message
exchange paths?
a. Service-oriented logical design modeling
b. Service-oriented conceptual architecture modeling
c. Service-oriented discovery and analysis modeling
d. Service-oriented business integration modeling ✔Correct Answer-a
Which of the following phases of DITSCAP includes the activities that are necessary for the
continuing operation of an accredited IT system in its computing environment and for
addressing the changing threats that a system faces throughout its life cycle?
a. Phase 3, Validation
b. Phase 1, Definition
c. Phase 2, Verification
d. Phase 4, Post Accreditation Phase ✔Correct Answer-d
Which of the following attacks causes software to fail and prevents the intended users from
accessing software?
a. Enabling attack
b. Reconnaissance attack
,c. Sabotage attack
d. Disclosure attack ✔Correct Answer-c
Which of the following NIST Special Publications documents provides a guideline on network
security testing?
a. NIST SP 800-42
b. NIST SP 800-53A
c. NIST SP 800-60
d. NIST SP 800-53
e. NIST SP 800-37
f. NIST SP 800-59 ✔Correct Answer-a
a.Which of the following is the duration of time and a service level within which a business
process must be restored after a disaster in order to avoid unacceptable consequences
associated with a break in business continuity?
a. RTO
b. RTA
c. RPO
d. RCO ✔Correct Answer-a
Microsoft security expert Michael Howard defines some heuristics for determining code review
in "A Process for Performing Security Code Reviews" . Which of the following heuristics increase
the application's attack surface? Each Correct Answer represents a complete solution. Choose all
that apply.
a. Code written C/C++/Assembly language
b. Code listening on a globally accessible network interface
c. Code that changes frequently
d. Anonymously accessible code
e. Code that runs by default
f. Code that runs in elevated context ✔Correct Answer-b,d,e,f
Which of the following methods determine the principle name of the current user and returns
the java.security.Principal object in the HttpServletRequest interface?
a. getUserPrincipal()
b. isUserInRole()
c. getRemoteUser()
d. getCallerPrincipal() ✔Correct Answer-a
, The LeGrand vulnerability-oriented risk management method is based on vulnerability analysis
and consists of four principal steps. Which of the following processes does the risk assessment
step include? Each Correct Answer represents a complete solution. Choose all that apply.
a. Remediation of a particular vulnerability
b. Cost-benefit examination of countermeasures
c. Identification of vulnerabilities
d. Assessment of attacks ✔Correct Answer-b,c,d
You are the project manager CUL project in your organization. You and the project team are
assessing the risk events and creating a probability and impact matrix for the identified risks.
Which one of the following statements best describes the requirements for the data type used
in qualitative risk analysis?
a. A qualitative risk analysis encourages biased data to reveal risk tolerances
b. A qualitative risk analysis required unbiased stakeholders with biased risk tolerances
c. A qualitative risk analysis requires accurate and unbiased data if it is to be credible
d. A qualitative risk analysis requires fast and simple data to complete the analysis. ✔Correct
Answer-c
Part of your change management plan details what should happen in the change control system
for your project. Theresa, a junior project manager, asks what the configuration management
activities are for scope changes. You tell her that all of the following are valid configuration
management activities except for which one?
a. Configuration identification
b. Configuration verification and auditing
c. Configuration status accounting
d. Configuration item costing ✔Correct Answer-d
The National Information Assurance Certification and Accreditation Process (NIACAP) is the
minimum standard process for the certification and accreditation of computer and
telecommunications systems that handle U.S. national security information. Which of the
following participants are required in a NIACAP security assessment? Each Correct Answer
represents a complete solution. Choose all that apply.
a. Certification agent
b. Designated Approving Authority
c. IS program manager
d. Information Assurance Manager
e. User representative ✔Correct Answer-a,b,c,e
Answers |Actual Complete Update |Already Graded A+
(Just Released)
Which of the following processes culminates in an agreement between key players that a
system in its current configuration and operation provides adequate protection controls?
a. Information Assurance (IA)
b. Information Systems Security Engineering (ISSE)
c. Certification & Accreditation (C&A)
d. Risk Management ✔Correct Answer-c
Which of the following cryptographic system services ensures that information will not be
disclosed to any unauthorized person on a local network?
a. Authentication
b. Integrity
c. Non-repudiation
d. Confidentiality ✔Correct Answer-d
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a
methodology for assessing the security of information systems. Which of the following FITSAF
levels shows that the procedures and controls have been implemented?
a. Level 2
b. Level 3
c. Level 5
d. Level 1
e. Level 4 ✔Correct Answer-b
In which of the following test methodologies do assessors use all available documentation and
work under no constraints, and attempt to circumvent the security features of an information
system?
a. Full operational test
b. Penetration test
c. Paper-test
d. Walk-through test ✔Correct Answer-b
Which of the following rated systems of the Orange Book has mandatory protection of the TCB?
,a. A-rated
b. B-rated
c. D-rated
d. C-rated ✔Correct Answer-b
Drop the appropriate value to complete the formula.
Single loss expectancy = Asset value ($) x ___________
a. Exposure Factor (EF)
b. Annual Loss Expectancy (ALE)
c. Annualized Rate of Occurrence (ARO) ✔Correct Answer-a
FIPS 199 defines the three levels of potential impact on organizations. Which of the following
potential impact levels shows limited adverse affects on organizational operations,
organizational assets, or individuals?
a. Moderate
b. Low
c. Medium
d. High ✔Correct Answer-b
Which of the following life cycle model activities establishes service relationships and message
exchange paths?
a. Service-oriented logical design modeling
b. Service-oriented conceptual architecture modeling
c. Service-oriented discovery and analysis modeling
d. Service-oriented business integration modeling ✔Correct Answer-a
Which of the following phases of DITSCAP includes the activities that are necessary for the
continuing operation of an accredited IT system in its computing environment and for
addressing the changing threats that a system faces throughout its life cycle?
a. Phase 3, Validation
b. Phase 1, Definition
c. Phase 2, Verification
d. Phase 4, Post Accreditation Phase ✔Correct Answer-d
Which of the following attacks causes software to fail and prevents the intended users from
accessing software?
a. Enabling attack
b. Reconnaissance attack
,c. Sabotage attack
d. Disclosure attack ✔Correct Answer-c
Which of the following NIST Special Publications documents provides a guideline on network
security testing?
a. NIST SP 800-42
b. NIST SP 800-53A
c. NIST SP 800-60
d. NIST SP 800-53
e. NIST SP 800-37
f. NIST SP 800-59 ✔Correct Answer-a
a.Which of the following is the duration of time and a service level within which a business
process must be restored after a disaster in order to avoid unacceptable consequences
associated with a break in business continuity?
a. RTO
b. RTA
c. RPO
d. RCO ✔Correct Answer-a
Microsoft security expert Michael Howard defines some heuristics for determining code review
in "A Process for Performing Security Code Reviews" . Which of the following heuristics increase
the application's attack surface? Each Correct Answer represents a complete solution. Choose all
that apply.
a. Code written C/C++/Assembly language
b. Code listening on a globally accessible network interface
c. Code that changes frequently
d. Anonymously accessible code
e. Code that runs by default
f. Code that runs in elevated context ✔Correct Answer-b,d,e,f
Which of the following methods determine the principle name of the current user and returns
the java.security.Principal object in the HttpServletRequest interface?
a. getUserPrincipal()
b. isUserInRole()
c. getRemoteUser()
d. getCallerPrincipal() ✔Correct Answer-a
, The LeGrand vulnerability-oriented risk management method is based on vulnerability analysis
and consists of four principal steps. Which of the following processes does the risk assessment
step include? Each Correct Answer represents a complete solution. Choose all that apply.
a. Remediation of a particular vulnerability
b. Cost-benefit examination of countermeasures
c. Identification of vulnerabilities
d. Assessment of attacks ✔Correct Answer-b,c,d
You are the project manager CUL project in your organization. You and the project team are
assessing the risk events and creating a probability and impact matrix for the identified risks.
Which one of the following statements best describes the requirements for the data type used
in qualitative risk analysis?
a. A qualitative risk analysis encourages biased data to reveal risk tolerances
b. A qualitative risk analysis required unbiased stakeholders with biased risk tolerances
c. A qualitative risk analysis requires accurate and unbiased data if it is to be credible
d. A qualitative risk analysis requires fast and simple data to complete the analysis. ✔Correct
Answer-c
Part of your change management plan details what should happen in the change control system
for your project. Theresa, a junior project manager, asks what the configuration management
activities are for scope changes. You tell her that all of the following are valid configuration
management activities except for which one?
a. Configuration identification
b. Configuration verification and auditing
c. Configuration status accounting
d. Configuration item costing ✔Correct Answer-d
The National Information Assurance Certification and Accreditation Process (NIACAP) is the
minimum standard process for the certification and accreditation of computer and
telecommunications systems that handle U.S. national security information. Which of the
following participants are required in a NIACAP security assessment? Each Correct Answer
represents a complete solution. Choose all that apply.
a. Certification agent
b. Designated Approving Authority
c. IS program manager
d. Information Assurance Manager
e. User representative ✔Correct Answer-a,b,c,e