CSSLP: Certified Secure Software Lifecycle Professional — Free Practice Questions
10 free sample questions from a bank of 338, with the correct answers and explanations. No signup required — start practising right now.
1You work as a Network Auditor for Net Perfect Inc. The company has a Windows-based network. While auditing the company's network, you are facing problems
in searching the faults and other entities that belong to it. Which of the following risks may occur due to the existence of these problems?
Residual risk
Secondary risk
Detection risk
Inherent risk
Answer: A
2The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of
computer and telecommunications systems that handle U.S. national security information. Which of the following participants are required in a NIACAP security
assessment? Each correct answer represents a part of the solution. Choose all that apply.
Certification agent
Designated Approving Authority
IS program manager
Information Assurance Manager
User representative
Answer: A, C, D
3DRAG DROP
Drop the appropriate value to complete the formula.
Select and Place:
Answer:
4Which of the following penetration testing techniques automatically tests every phone line in an exchange and tries to locate modems that are attached to the
network?
Demon dialing
Sniffing
Social engineering
Dumpster diving
Answer: A, B
5Which of the following roles is also known as the accreditor?
Data owner
Chief Risk Officer
Chief Information Officer
Designated Approving Authority
Answer: D
6DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and confidentiality levels. Which of the
following MAC levels requires high integrity and medium availability?
MAC III
MAC IV
MAC I
MAC II
Answer: D
7Microsoft software security expert Michael Howard defines some heuristics for determining code review in "A Process for Performing Security Code Reviews".
Which of the following heuristics increase the application's attack surface? Each correct answer represents a complete solution. Choose all that apply.
Code written in C/C++/assembly language
Code listening on a globally accessible network interface
Code that changes frequently
Anonymously accessible code
Code that runs by default
Code that runs in elevated context
Answer: B, D, E, F
8Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
Authentication
Integrity
Non-repudiation
Confidentiality
Answer: D
9What are the various activities performed in the planning phase of the Software Assurance Acquisition process? Each correct answer represents a complete
solution. Choose all that apply.
Develop software requirements.
Implement change control procedures.
Develop evaluation criteria and evaluation plan.
Create acquisition strategy.
Answer: A, C, D
10You work as a project manager for BlueWell Inc. You are working on a project and the management wants a rapid and cost-effective means for establishing
priorities for planning risk responses in your project. Which risk management process can satisfy management's objective for your project?