Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC Other Certification CSSLP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CSSLP Premium Access

View all detail and faqs for the CSSLP exam


809 Students Passed

90% Average Score

90% Same Questions
Viewing page 3 out of 11 pages
Viewing questions 21-30 out of questions
Questions # 21:

Drag and drop the appropriate external constructs in front of their respective functions.

Question # 21

Options:

Questions # 22:

Which of the following sections come under the ISO/IEC 27002 standard?

Options:

A.

Security policy

B.

Asset management

C.

Financial assessment

D.

Risk assessment

Questions # 23:

You work as a security manager for BlueWell Inc. You are going through the NIST SP 800-37 C&A methodology, which is based on four well defined phases. In which of the following phases of NIST SP 800-37 C&A methodology does the security categorization occur?

Options:

A.

Security Accreditation

B.

Security Certification

C.

Continuous Monitoring

D.

Initiation

Questions # 24:

Which of the following is an open source network intrusion detection system?

Options:

A.

NETSH

B.

Macof

C.

Sourcefire

D.

Snort

Questions # 25:

You work as a security engineer for BlueWell Inc. According to you, which of the following DITSCAP/NIACAP model phases occurs at the initiation of the project, or at the initial C&A effort of a legacy system?

Options:

A.

Validation

B.

Definition

C.

Verification

D.

Post Accreditation

Questions # 26:

Which of the following statements are true about declarative security? Each correct answer represents a complete solution. Choose all that apply.

Options:

A.

It is employed in a layer that relies outside of the software code or uses attributes of the code.

B.

It applies the security policies on the software applications at their runtime.

C.

In this security, authentication decisions are made based on the business logic.

D.

In this security, the security decisions are based on explicit statements.

Questions # 27:

The Data and Analysis Center for Software (DACS) specifies three general principles for software assurance which work as a framework in order to categorize various secure design principles. Which of the following principles and practices does the General Principle 1 include? Each correct answer represents a complete solution. Choose two.

Options:

A.

Principle of separation of privileges, duties, and roles

B.

Assume environment data is not trustworthy

C.

Simplify the design

D.

Principle of least privilege

Questions # 28:

Which of the following is the process of finding weaknesses in cryptographic algorithms and obtaining the plaintext or key from the ciphertext?

Options:

A.

Cryptographer

B.

Cryptography

C.

Kerberos

D.

Cryptanalysis

Questions # 29:

Which of the following specifies access privileges to a collection of resources by using the URL mapping?

Options:

A.

Code Access Security

B.

Security constraint

C.

Configuration Management

D.

Access Management

Questions # 30:

What project management plan is most likely to direct the quantitative risk analysis process for a project in a matrix environment?

Options:

A.

Risk analysis plan

B.

Staffing management plan

C.

Risk management plan

D.

Human resource management plan

Viewing page 3 out of 11 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.