• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

CSSLP Exam Domain 2 - Secure Software Requirements with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Document preview thumbnail
Preview 2 out of 5 pages

CSSLP Exam Domain 2 - Secure Software Requirements with all Correct & 100% Verified Answers |Latest Version |Already Graded A+

Content preview

CSSLP Exam Domain 2 - Secure Software Requirements
with all Correct & 100% Verified Answers |Latest Version
|Already Graded A+

Which of the following MUST be addressed by software security requirements? Choose the
BEST answer.
A. Technology used in building the application
B. Goals and objectives of the organization
C. Software quality requirements.
D. External auditor requirements ✔Correct Answer-B. Goals and objectives of the organization

Which of the following types of information is exempt from confidentiality requirements?
A. Directory information
B. Personally identifiable information (PII)
C. User's card holder data
D. Software architecture and network diagram ✔Correct Answer-A. Directory information

Requirements that are identified to protect against the destruction of information or the
software itself are commonly referred to as
A. confidentiality requirements
B. integrity requirements
C. availability requirements
D. authentication requirements ✔Correct Answer-C. availability requirements

The amount of time by which business operations need to be restored to service levels as
expectd by the business when there is a security breach or disaster is known as
A. Maximum Tolerable Downtime (MTD)
B. Mean Time Before Failure (MTBF)
C. Minimum Security Baselinee (MSB)
D. Recovery Time Objective (RTO) ✔Correct Answer-D. Recovery Time Objective (RTO)

The use of an individual's physical characteristics such as retinal blood patterns and fingertips
for validating and verifying the user's identity if referred to as
A. biometric authentication
B. forms authentication
C. digest authentication
D. integrated authentication ✔Correct Answer-A. biometric authentication

Which of the following policies is MOST likely to include the following requirement? "All
software processing financial transactions need to use more than one factor to verify the
identity of the entity requesting access"

, A. Authorization
B. Authentication
C. Auditing
D. Availability ✔Correct Answer-B. Authentication

A means of restricting access to objects based on the identity of subjects and/or groups to
which they belong, as mandated by the requested resource owner is the definition of
A. Non-discretionary Access Control (NDAC)
B. Discretionary Access Control (DAC)
C. Mandatory Access Control (MAC)
D. Role based Access Control ✔Correct Answer-B. Discretionary Access Control (DAC)

Requirements which when implemented can help to build a history of events that occurred in
the software are known as
A. authentication requirements
B. archiving requirements
C. accountability requirements
D. authorization requirements ✔Correct Answer-C. accountability requirements

Which of the following is the PRIMARY reason for an application to be susceptible to a Man-in-
the-Middle (MITM) attack?
A. Improper session management
B. Lack of auditing
C. Improper archiving
D. Lack of encryption ✔Correct Answer-A. Improper session management

The process of eliciting concrete software security requirements from high level regulatory and
organizational directives and mandates in the requirements phase of the SDLC is also known as
A. threat modeling
B. policy decomposition
C. subject-object modeling
D. misuse case generation. ✔Correct Answer-B. policy decomposition

The FIRST step in the Protection Needs Elicitation (PNE) process is to
A. engage the customer
B. model information management
C. identify least privilege applications
D. conduct threat modeling and analysis ✔Correct Answer-A. engage the customer

A Requirements Traceability Matrix (RTM) that includes security requirements can be used for
all of the following except
A. ensuring scope creep does not occur
B. validating and communicating user requirements
C. determining resource allocations

Document information

Uploaded on
September 28, 2026
Number of pages
5
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$15.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Studyclub
3.6
(14)
Sold
69
Followers
1
Items
13382
Last sold
6 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions