CSSLP Test Domain 3 - Secure Software Design with all
Correct & 100% Verified Answers |Actual Complete
Update |Already Graded A+
What is the OWASP Top 10? ✔Correct Answer-A set of common vulnerable components of
web applications and APIs, ranked in descending order from most commonly exploited
What were the 3 new vulnerability types that were introduced in OWASP Top 10 2021?
✔Correct Answer-- A04: Insecure Design
- A08: Software & Data Integrity Failures
- A10: Server-Side Request Forgery (SSRF)
What are the benefits of Secure by Design adoption? ✔Correct Answer-- Resilient and
recoverable software
- Quality, maintainable software
- Minimal redesign consistency
- Business logic flaws addressed
What is Resilient and Recoverable software? ✔Correct Answer-Decreased likelihood of attack
errors
What is Quality maintainable software? ✔Correct Answer-Software that is less prone to errors
What is Minimal Redesign & Consistency? ✔Correct Answer-A reduced need for redesign,
meaning more consistent software
What is Business logic flaws addressed? ✔Correct Answer-Uncovering design and business
logic flaws through design
Once identified, what should be done with flaws and bugs? ✔Correct Answer-They should be
addressed/mitigated
What are the 6 parts of the STRIDE threat model? ✔Correct Answer-1. Spoofing
2. Tampering
3. Repudiation
4. Info Disclosure
5. DDoS
6. Elevation of Privilege
What are the 5 parts of the DREAD threat model? ✔Correct Answer-1. Damage potential
2. Reproducibility
,3. Exploitability
4. Affected users
5. Discoverability
What is the main method of identifying design flaws in logical software operation? ✔Correct
Answer-Security architecture and design reviews
What are 3 elements are commonly seen across all threat modelling methodologies?
✔Correct Answer-- Threats
- Vulnerabilities/control gaps
- Countermeasures
What is confidentiality design? ✔Correct Answer-Engineering of disclosure protection
mechanisms in software using cryptographic and masking techniques.
What are the 2 methods of cryptography? What algorithms fit under them? ✔Correct
Answer-Overt
> Encryption (Symmetric/Asymmetric)
> Hashing
Covert
> Steganography
> Digital Watermarking
How is Key Exchange and Management performed in Symmetric Algorithms? ✔Correct
Answer-Both the originator and the receiver must have a mechanism in place to share keys
without compromising its secrecy.
Why is Scalability difficult in Symmetric Algorithms? ✔Correct Answer-There needs to be as
many keys as there are senders and recipients
How are keys used in Asymmetric cryptography? ✔Correct Answer-- Only one sender can give
the same public key to all recipients
- Public keys can only be created by the owner of the matching private key
- Recipients of encrypted messages use the matching public key to decrypt messages
What infrastructure is used for Key Exchange and Management in Asymmetric Algorithms?
✔Correct Answer-They use the Public Key Infrastructure (PKI) technique for key identification,
exchange and management. PKI uses digital certificates to make automation of these tasks
possible
Why is Scalability easy in Asymmetric Algorithms? ✔Correct Answer-In asymmetric
cryptography, there only needs to be 2 keys per user; a private and a public one. The public one
can be distributed to anyone who wishes to communicate with the sender, who holds the
private key.
,How do Asymmetric Algorithms ensure Non-Repudiation? ✔Correct Answer-It provides the
receiver, assurance of proof of origin. The sender cannot deny sending any messages when it is
encrypted using their private key
What is the current internationally recognised digital certificate standard, and what different
types are there? ✔Correct Answer-ITU X.509 (v3):
> Personal
> Server
> Extended Validation (EV)
> Software publisher
What are Personal Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Identification of
individuals to authenticate them with a server
What are Server Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Used to identify
servers with a connecting client, over the Secure Socket Layer (SSL)
What are Extended Validation (EV) certificates in X.509 (v3) PKI used for? ✔Correct Answer-
Ensures that sites that users are connecting to are legitimate, as these certificates undergo
more extensive validation than normal certificates.
What are Software Publisher in X.509 (v3) PKI used for? ✔Correct Answer-They are used to
sign software that will be distributed on the internet, by acting in a strictly informative capacity
to inform the software user that the certificate is signed by a trusted software publishers
certificate authority (CA)
What are Digital Signatures? ✔Correct Answer-They are certificates that hold the 'signature'
of the certificate authority (CA) that verified and issued a digital certificate.
What are the 6 stages of the Key Management Framework? ✔Correct Answer-1. Generation
2. Exchange
3. Storage
4. Rotation
5. Archiving
6. Destruction
What is integrity design? ✔Correct Answer-Assurance that there is no unauthorised
modification of the software or data.
What is a message digest, and what can the recipient do with it? ✔Correct Answer-A message
and a hash value computed by the author of the message:
, > The recipient can compute the hash using the same algorithm as the sender, and then
compare their computed value with the hash value that was provided in the message digest. If
the values match, then the message is unaltered.
What technique ensures a hash digest is protected against the birthday attack? How is this
done? ✔Correct Answer-Salting:
> Adds random bytes when computing the hash, so that the same message hashed by an
attacker will not produce the same digest
Where is hash salting commonly used in applications with users? What type of attack does this
mitigate? ✔Correct Answer-User authentication:
> Mitigates rainbow table and dictionary attacks
What is referential integrity in relation to databases? How does it work? ✔Correct Answer-It
ensures that data is not left in an orphaned state:
> A primary key identifies each row in a table
> Primary keys are referenced as foreign keys in another table
What is resource locking in relation to databases, what is the main risk with misconfiguring it?
✔Correct Answer-When two concurrent operations are not allowed on the same object:
> The main risk is deadlocks and denial of service (DoS)
What is availability design, how is it determined? ✔Correct Answer-Software requirements
that mandate the need for continued business operations:
> Determined with business impact analysis
What does data replication regulate, and what is architecture behind it? ✔Correct Answer-It
ensures that Maximum Tolerable Downtime (MTD) and Recovery Time Objective (RTO) are both
within acceptable levels:
> It uses a primary/secondary node architecture, in which the primary node updates are
propagated to the secondary nodes
What is computing failover? ✔Correct Answer-The automatic switching from an active asset,
to a redundant one
What is the main principle of scalability design? ✔Correct Answer-The ability of software to
handle increasing amounts of work without degradation in functionality or performance.
What is the difference between Vertical (Up) and Horizontal (Out) scaling? ✔Correct Answer--
Vertical adds additional resources to the existing node
- Horizontal means adding additional nodes with the same software on them to the workload
What are the considerations of authentication design? ✔Correct Answer-- MFA & SSO
- Requirements for user experience
Correct & 100% Verified Answers |Actual Complete
Update |Already Graded A+
What is the OWASP Top 10? ✔Correct Answer-A set of common vulnerable components of
web applications and APIs, ranked in descending order from most commonly exploited
What were the 3 new vulnerability types that were introduced in OWASP Top 10 2021?
✔Correct Answer-- A04: Insecure Design
- A08: Software & Data Integrity Failures
- A10: Server-Side Request Forgery (SSRF)
What are the benefits of Secure by Design adoption? ✔Correct Answer-- Resilient and
recoverable software
- Quality, maintainable software
- Minimal redesign consistency
- Business logic flaws addressed
What is Resilient and Recoverable software? ✔Correct Answer-Decreased likelihood of attack
errors
What is Quality maintainable software? ✔Correct Answer-Software that is less prone to errors
What is Minimal Redesign & Consistency? ✔Correct Answer-A reduced need for redesign,
meaning more consistent software
What is Business logic flaws addressed? ✔Correct Answer-Uncovering design and business
logic flaws through design
Once identified, what should be done with flaws and bugs? ✔Correct Answer-They should be
addressed/mitigated
What are the 6 parts of the STRIDE threat model? ✔Correct Answer-1. Spoofing
2. Tampering
3. Repudiation
4. Info Disclosure
5. DDoS
6. Elevation of Privilege
What are the 5 parts of the DREAD threat model? ✔Correct Answer-1. Damage potential
2. Reproducibility
,3. Exploitability
4. Affected users
5. Discoverability
What is the main method of identifying design flaws in logical software operation? ✔Correct
Answer-Security architecture and design reviews
What are 3 elements are commonly seen across all threat modelling methodologies?
✔Correct Answer-- Threats
- Vulnerabilities/control gaps
- Countermeasures
What is confidentiality design? ✔Correct Answer-Engineering of disclosure protection
mechanisms in software using cryptographic and masking techniques.
What are the 2 methods of cryptography? What algorithms fit under them? ✔Correct
Answer-Overt
> Encryption (Symmetric/Asymmetric)
> Hashing
Covert
> Steganography
> Digital Watermarking
How is Key Exchange and Management performed in Symmetric Algorithms? ✔Correct
Answer-Both the originator and the receiver must have a mechanism in place to share keys
without compromising its secrecy.
Why is Scalability difficult in Symmetric Algorithms? ✔Correct Answer-There needs to be as
many keys as there are senders and recipients
How are keys used in Asymmetric cryptography? ✔Correct Answer-- Only one sender can give
the same public key to all recipients
- Public keys can only be created by the owner of the matching private key
- Recipients of encrypted messages use the matching public key to decrypt messages
What infrastructure is used for Key Exchange and Management in Asymmetric Algorithms?
✔Correct Answer-They use the Public Key Infrastructure (PKI) technique for key identification,
exchange and management. PKI uses digital certificates to make automation of these tasks
possible
Why is Scalability easy in Asymmetric Algorithms? ✔Correct Answer-In asymmetric
cryptography, there only needs to be 2 keys per user; a private and a public one. The public one
can be distributed to anyone who wishes to communicate with the sender, who holds the
private key.
,How do Asymmetric Algorithms ensure Non-Repudiation? ✔Correct Answer-It provides the
receiver, assurance of proof of origin. The sender cannot deny sending any messages when it is
encrypted using their private key
What is the current internationally recognised digital certificate standard, and what different
types are there? ✔Correct Answer-ITU X.509 (v3):
> Personal
> Server
> Extended Validation (EV)
> Software publisher
What are Personal Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Identification of
individuals to authenticate them with a server
What are Server Certificates in X.509 (v3) PKI used for? ✔Correct Answer-Used to identify
servers with a connecting client, over the Secure Socket Layer (SSL)
What are Extended Validation (EV) certificates in X.509 (v3) PKI used for? ✔Correct Answer-
Ensures that sites that users are connecting to are legitimate, as these certificates undergo
more extensive validation than normal certificates.
What are Software Publisher in X.509 (v3) PKI used for? ✔Correct Answer-They are used to
sign software that will be distributed on the internet, by acting in a strictly informative capacity
to inform the software user that the certificate is signed by a trusted software publishers
certificate authority (CA)
What are Digital Signatures? ✔Correct Answer-They are certificates that hold the 'signature'
of the certificate authority (CA) that verified and issued a digital certificate.
What are the 6 stages of the Key Management Framework? ✔Correct Answer-1. Generation
2. Exchange
3. Storage
4. Rotation
5. Archiving
6. Destruction
What is integrity design? ✔Correct Answer-Assurance that there is no unauthorised
modification of the software or data.
What is a message digest, and what can the recipient do with it? ✔Correct Answer-A message
and a hash value computed by the author of the message:
, > The recipient can compute the hash using the same algorithm as the sender, and then
compare their computed value with the hash value that was provided in the message digest. If
the values match, then the message is unaltered.
What technique ensures a hash digest is protected against the birthday attack? How is this
done? ✔Correct Answer-Salting:
> Adds random bytes when computing the hash, so that the same message hashed by an
attacker will not produce the same digest
Where is hash salting commonly used in applications with users? What type of attack does this
mitigate? ✔Correct Answer-User authentication:
> Mitigates rainbow table and dictionary attacks
What is referential integrity in relation to databases? How does it work? ✔Correct Answer-It
ensures that data is not left in an orphaned state:
> A primary key identifies each row in a table
> Primary keys are referenced as foreign keys in another table
What is resource locking in relation to databases, what is the main risk with misconfiguring it?
✔Correct Answer-When two concurrent operations are not allowed on the same object:
> The main risk is deadlocks and denial of service (DoS)
What is availability design, how is it determined? ✔Correct Answer-Software requirements
that mandate the need for continued business operations:
> Determined with business impact analysis
What does data replication regulate, and what is architecture behind it? ✔Correct Answer-It
ensures that Maximum Tolerable Downtime (MTD) and Recovery Time Objective (RTO) are both
within acceptable levels:
> It uses a primary/secondary node architecture, in which the primary node updates are
propagated to the secondary nodes
What is computing failover? ✔Correct Answer-The automatic switching from an active asset,
to a redundant one
What is the main principle of scalability design? ✔Correct Answer-The ability of software to
handle increasing amounts of work without degradation in functionality or performance.
What is the difference between Vertical (Up) and Horizontal (Out) scaling? ✔Correct Answer--
Vertical adds additional resources to the existing node
- Horizontal means adding additional nodes with the same software on them to the workload
What are the considerations of authentication design? ✔Correct Answer-- MFA & SSO
- Requirements for user experience