Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free ISC2 Certified Secure Software Lifecycle Professional CSSLP Exam Questions

Page: 1 / 24 Total 357 questions

Want more questions? Get Premium Access.

Question 1

Which of the following models uses a directed graph to specify the rights that a subject can transfer to an object or that a subject can take from another subject?

Correct Answer: A. Take-Grant Protection Model
Explanation:

The take-grant protection model is a formal model used in the field of computer security to establish or disprove the safety of a given

computer system that follows specific rules. It shows that for specific systems the question of safety is decidable in linear time, which is in

general undecidable.

The model represents a system as directed graph, where vertices are either subjects or objects. The edges between them are labeled and

the label indicates the rights that the source of the edge has over the destination. Two rights occur in every instance of the model: take and

grant. They play a special role in the graph rewriting rules describing admissible changes of the graph.

Answer D is incorrect. The access matrix is a straightforward approach that provides access rights to subjects for objects.

Answer C is incorrect. The Bell-LaPadula model deals only with the confidentiality of classified material. It does not address integrity or

availability.

Answer B is incorrect. The integrity model was developed as an analog to the Bell-LaPadula confidentiality model and then became

more sophisticated to address additional integrity requirements.


Question 2

Which of the following penetration testing techniques automatically tests every phone line in an exchange and tries to locate modems that are attached to the network?

Correct Answer: A. Demon dialing
Explanation:

The demon dialing technique automatically tests every phone line in an exchange and tries to locate modems that are attached to the

network. Information about these modems can then be used to attempt external unauthorized access.

Answer B is incorrect. In sniffing, a protocol analyzer is used to capture data packets that are later decoded to collect information such

as passwords or infrastructure configurations.

Answer D is incorrect. Dumpster diving technique is used for searching paper disposal areas for unshredded or otherwise improperly

disposed-of reports.

Answer C is incorrect. Social engineering is the most commonly used technique of all, getting information (like passwords) just by

asking for them.


Question 3

Which of the following are examples of the application programming interface (API)?

Each correct answer represents a complete solution. Choose three.

Correct Answer: B. PHP; C. .NET; D. Perl
Explanation:

Perl, .NET, and PHP are examples of the application programming interface (API). API is a set of routines, protocols, and tools that users can

use to work with a component, application, or operating system. It consists of one or more DLLs that provide specific functionality. API helps in

reducing the development time of applications by reducing application code. Most operating environments, such as MS-Windows, provide an

API so that programmers can write applications consistent with the operating environment.

Answer A is incorrect. HTML stands for Hypertext Markup Language. It is a set of markup symbols or codes used to create Web pages

and define formatting specifications. The markup tells the Web browser how to display the content of the Web page.


Question 4

The DARPA paper defines various procedural patterns to perform secure system development practices. Which of the following patterns does it include?

Each correct answer represents a complete solution. Choose three.

Correct Answer: B. Document the server configuration; C. Patch proactively; D. Red team the design
Explanation:

The following procedural patterns are defined by the DARPA paper in order to perform secure software development practices:

Build the server from the ground up: It includes the following features:

Build the server from the ground up.

Identify the default installation of the operating system and applications.

Support hardening procedures to remove unnecessary services.

Identify a vulnerable service for ongoing risk management.

Choose the right stuff: It defines guidelines to select right commercial off-the-shelf (COTS) components and decide whether to use and

build custom components.

Document the server configuration: It supports the creation of an initial configuration baseline and tracks all modifications made to

servers and application configurations.

Patch proactively: It supports in applying patches as soon as they are available rather than waiting until the systems cooperate.

Red team the design: It supports an independent security assessment from the perspective of an attacker in the quality assurance or

testing stage. An independent security assessment is helpful in addressing a security issue before it occurs.

Answer A is incorrect. Hidden implementation pattern is not defined in the DARPA paper. This pattern is applicable to software

assurance in general. Hidden implementation limits the ability of an attacker to distinguish the internal workings of an application.

Answer E is incorrect. Password propagation is not defined in the DARPA paper. This pattern is applicable to aspects of authentication

in a Web application. Password propagation provides an alternative by requiring that a user's authentication credentials be verified by the

database before providing access to that user's data.


Question 5

Which of the following NIST documents provides a guideline for identifying an information system as a National Security System?

Correct Answer: B. NIST SP 800-59
Explanation:

NIST has developed a suite of documents for conducting Certification & Accreditation (C&A). These documents are as follows:

NIST Special Publication 800-37: This document is a guide for the security certification and accreditation of Federal Information

Systems.

NIST Special Publication 800-53: This document provides a guideline for security controls for Federal Information Systems.

NIST Special Publication 800-53A. This document consists of techniques and procedures for verifying the effectiveness of security

controls in Federal Information System.

NIST Special Publication 800-59: This document is a guideline for identifying an information system as a National Security System.

NIST Special Publication 800-60: This document is a guide for mapping types of information and information systems to security

objectives and risk levels.


Question 6

Which of the following elements of BCP process includes the areas of plan implementation, plan testing, and ongoing plan maintenance, and also involves defining and documenting the continuity strategy?

Correct Answer: A. Business continuity plan development
Explanation:

The business continuity plan development refers to the utilization of the information collected in the Business Impact Analysis (BIA) for the

creation of the recovery strategy plan to support the critical business functions. The information gathered from the BIA is mapped out to make

a strategy for creating a continuity plan. The business continuity plan development process includes the areas of plan implementation, plan

testing, and ongoing plan maintenance. This phase also consists of defining and documenting the continuity strategy.

Answer C is incorrect. The scope and plan initiation process in BCP symbolizes the beginning of the BCP process. It emphasizes on

creating the scope and the additional elements required to define the parameters of the plan.

The scope and plan initiation phase embodies a check of the company's operations and support services. The scope activities include creating

a detailed account of the work required, listing the resources to be used, and defining the management practices to be employed.

Answer B is incorrect. The business impact assessment is a method used to facilitate business units to understand the impact of a

disruptive event. This phase includes the execution of a vulnerability assessment. This process makes out the mission-critical areas and

business processes that are important for the survival of business.

It is similar to the risk assessment process. The function of a business impact assessment process is to create a document, which is used to

help and understand what impact a disruptive event would have on the business.

Answer D is incorrect. The plan approval and implementation process involves creating enterprise-wide awareness of the plan, getting

the final senior management signoff, and implementing a maintenance procedure for updating the plan as required.


Question 7

Which of the following attacks causes software to fail and prevents the intended users from accessing software?

Correct Answer: C. Sabotage attack
Explanation:

A sabotage attack is an attack that causes software to fail. It also prevents the intended users from accessing software. A sabotage attack is

referred to as a denial of service (DoS) or compromise of availability.

Answer B is incorrect. The reconnaissance attack enables an attacker to collect information about software and operating environment.

Answer D is incorrect. The disclosure attack exposes the revealed data to an attacker.

Answer A is incorrect. The enabling attack delivers an easy path for other attacks.


Question 8

What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: A. Initiate IA implementation plan.; B. Develop DIACAP strategy.; C. Assign IA controls.; D. Assemble DIACAP team.; E. Register system with DoD Component IA Program.
Explanation:

The Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) is a process defined by the United States

Department of Defense (DoD) for managing risk.

The subordinate tasks of the Initiate and Plan IA C&A phase are as follows:

Register system with DoD Component IA Program.

Assign IA controls.

Assemble DIACAP team.

Develop DIACAP strategy.

Initiate IA implementation plan.

Answer F is incorrect. Validation activities are conducted in the second phase of the DIACAP process, i.e., Implement and Validate

Assigned IA Controls.


Question 9

The rights of an author or a corporation to make profit from the creation of their products (such as software, music, etc.) are protected by the Intellectual Property law. Which of the following are the components of the Intellectual Property law?

Each correct answer represents a part of the solution. Choose two.

Correct Answer: B. Industrial Property law; C. Copyright law
Explanation:

The Industrial Property law and the Copyright law are the components of the Intellectual Property law.


Question 10

FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls are tested and reviewed?

Correct Answer: A. Level 4
Explanation:

The following are the five levels of FITSAF based on SEI's Capability Maturity Model (CMM):

Level 1: The first level reflects that an asset has documented a security policy.

Level 2: The second level shows that the asset has documented procedures and controls to implement the policy.

Level 3: The third level indicates that these procedures and controls have been implemented.

Level 4: The fourth level shows that the procedures and controls are tested and reviewed.

Level 5: The fifth level is the final level and shows that the asset has procedures and controls fully integrated into a comprehensive

program.


Question 11

Which of the following are Service Level Agreement (SLA) structures as defined by ITIL?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B. Service Based; D. Customer Based; E. Multi-Level
Explanation:

ITIL defines 3 types of Service Level Agreement (SLA) structures, which are as follows:

1.Customer Based: It covers all services used by an individual customer group.

2.Service Based: It is one service for all customers.

3.Multi-Level: Some examples of Multi-Level SLA are 3 Tier SLA encompassing Corporate and Customer & Service Layers.

Answer C and A are incorrect. There are no such SLA structures as Segment Based and Component Based.


Question 12

You are the project manager of QSL project for your organization. You are working with your project team and several key stakeholders to create a diagram that shows how various elements of a system interrelate and the mechanism of causation within the system. What diagramming technique are you using as a part of the risk identification process?

Correct Answer: D. System or process flowcharts
Explanation:

In this example you are using a system or process flowchart. These can help identify risks within the process flow, such as bottlenecks or

redundancy.

Answer A is incorrect. A cause and effect diagram, also known as an Ishikawa or fishbone diagram, can reveal causal factors to the

effect to be solved.

Answer B is incorrect. An influence diagram shows causal influences, time ordering of events and relationships among variables and

outcomes.

Answer C is incorrect. Predecessor and successor diagramming is not a valid risk identification term.


Question 13

Which of the following test methods has the objective to test the IT system from the viewpoint of a threat-source and to identify potential failures in the IT system protection schemes?

Correct Answer: B. Penetration testing
Explanation:

The goal of penetration testing is to examine the IT system from the perspective of a threat-source, and to identify potential failures in the IT

system protection schemes. Penetration testing, when performed in the risk assessment process, is used to assess an IT system's capability

to survive with the intended attempts to thwart system security.

Answer A is incorrect. The objective of ST&E is to ensure that the applied controls meet the approved security specification for the

software and hardware and implement the organization's security policy or meet industry standards.


Question 14

Which of the following roles is also known as the accreditor?

Correct Answer: D. Designated Approving Authority
Explanation:

Designated Approving Authority (DAA) is also known as the accreditor.

Answer A is incorrect. The data owner (information owner) is usually a member of management, in charge of a specific business unit,

and is ultimately responsible for the protection and use of a specific subset of information.

Answer B is incorrect. A Chief Risk Officer (CRO) is also known as Chief Risk Management Officer (CRMO). The Chief Risk Officer or Chief

Risk Management Officer of a corporation is the executive accountable for enabling the efficient and effective governance of significant risks,

and related opportunities, to a business and its various segments. Risks are commonly categorized as strategic, reputational, operational,

financial, or compliance-related. CRO's are accountable to the Executive Committee and The Board for enabling the business to balance risk

and reward. In more complex organizations, they are generally responsible for coordinating the organization's Enterprise Risk Management

(ERM) approach.

Answer C is incorrect. The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the

most senior executive in an enterprise responsible for the information technology and computer systems that support enterprise goals. The

CIO plays the role of a leader and reports to the chief executive officer, chief operations officer, or chief financial officer. In military

organizations, they report to the commanding officer.


Question 15

You and your project team have identified the project risks and now are analyzing the probability and impact of the risks. What type of analysis of the risks provides a quick and high-level review of each identified risk event?

Correct Answer: B. Qualitative risk analysis
Explanation:

Qualitative risk analysis is a high-level, fast review of the risk event. Qualitative risk analysis qualifies the risk events for additional analysis.