CramPDF Co., ltd provides valid exam cram PDF & dumps PDF materials to help candidates pass exam certainly. If you want to get certifications in the short time please choose CramPDF exam cram or dumps PDF file.

[Oct 21, 2023] CSSLP Sample with Accurate & Updated Questions [Q145-Q163]

Share

[Oct 21, 2023] CSSLP Sample with Accurate & Updated Questions

CSSLP Exam Info and Free Practice Test | CramPDF


Conclusion

Getting the Certified Secure Software Lifecycle Professional certification can be achieved by passing one exam. The candidates can get the passing score by following the blueprint of the test and understanding the skills they have to develop. Also, using verified training materials is an effective strategy that can lead to success. Therefore, the candidates can use the books available on Amazon or enroll in instructor-led online or classroom sessions, where they can understand the exam topics much better and as a result, nail the official validation in one go.


Target Audience

The target candidates for the CSSLP certification are the professionals with the expertise in incorporating security practices, including auditing, authentication, and authorization, into different phases of SDLC (Software Development Lifecycle). This certificate covers software design all through to the implementation stage, testing, and deployment.

 

NEW QUESTION # 145
Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one?

  • A. Configuration Item Costing
  • B. Configuration Verification and Auditing
  • C. Configuration Identification
  • D. Configuration Status Accounting

Answer: A

Explanation:
Configuration item cost is not a valid activity for configuration management. Cost changes are managed by the cost change control system; configuration management is concerned with changes to the features and functions of the project deliverables.


NEW QUESTION # 146
Elizabeth is a project manager for her organization and she finds risk management to be very difficult for her to manage. She asks you, a lead project manager, at what stage in the project will risk management become easier. What answer best resolves the difficulty of risk management practices and the effort required?

  • A. Risk management is an iterative process and never becomes easier.
  • B. Risk management only becomes easier when the project is closed.
  • C. Risk management only becomes easier the more often it is practiced.
  • D. Risk management only becomes easier when the project moves into project execution.

Answer: C

Explanation:
Explanation/Reference:
Explanation: According to the PMBOK, "Like many things in project management, the more it is done the easier the practice becomes." AnswerB is incorrect. This answer is not the best choice for the project.
AnswerA is incorrect. Risk management likely becomes more difficult in project execution that in other
stages of the project. AnswerC is incorrect. Risk management does become easier the more often it is done.


NEW QUESTION # 147
Continuous Monitoring is the fourth phase of the security certification and accreditation process. What activities are performed in the Continuous Monitoring process? Each correct answer represents a complete solution. Choose all that apply.

  • A. Security control monitoring and impact analyses of changes to the information system
  • B. Configuration management and control
  • C. Security accreditation decision
  • D. Status reporting and documentation
  • E. Security accreditation documentation

Answer: A,B,D

Explanation:
Explanation/Reference:
Explanation: Continuous Monitoring is the fourth phase of the security certification and accreditation process. The Continuous Monitoring process consists of the following three main activities: Configuration management and control Security control monitoring and impact analyses of changes to the information system Status reporting and documentation The objective of these tasks is to observe and evaluate the information system security controls during the system life cycle. These tasks determine whether the changes that have occurred will negatively impact the system security. Answer: A and C are incorrect.
Security accreditation decision and security accreditation documentation are the two tasks of the security accreditation phase.


NEW QUESTION # 148
Which of the following methods offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling?

  • A. Service-oriented modeling framework (SOMF)
  • B. Sherwood Applied Business Security Architecture (SABSA)
  • C. Service-oriented architecture (SOA)
  • D. Service-oriented modeling and architecture (SOMA)

Answer: A

Explanation:
The service-oriented modeling framework (SOMF) has been proposed by author Michael Bell as a service-oriented modeling language for software development that employs disciplines and a holistic language to provide strategic solutions to enterprise problems. The service-oriented modeling framework (SOMF) is a service-oriented development life cycle methodology. It offers a number of modeling practices and disciplines that contribute to a successful service-oriented life cycle management and modeling. The service-oriented modeling framework illustrates the major elements that identify the "what to do" aspects of a service development scheme. Answer B is incorrect. The service-oriented architecture (SOA) is a flexible set of design principles used during the phases of systems development and integration. Answer D is incorrect. The service-oriented modeling and architecture (SOMA) includes an analysis and design method that extends traditional object-oriented and component-based analysis and design methods to include concerns relevant to and supporting SOA. Answer C is incorrect. SABSA (Sherwood Applied Business Security Architecture) is a framework and methodology for Enterprise Security Architecture and Service Management. It is a model and a methodology for developing risk-driven enterprise information security architectures and for delivering security infrastructure solutions that support critical business initiatives.


NEW QUESTION # 149
Which of the following security design patterns provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data?

  • A. Account lockout
  • B. Secure assertion
  • C. Password propagation
  • D. Authenticated session

Answer: C

Explanation:
Password propagation provides an alternative by requiring that a user's authentication credentials be verified by the database before providing access to that user's data. Answer D is incorrect. Account lockout implements a limit on the incorrect password attempts to protect an account from automated password-guessing attacks. Answer B is incorrect. Authenticated session allows a user to access more than one access-restricted Web page without re-authenticating every page. It also integrates user authentication into the basic session model. Answer A is incorrect. Secure assertion distributes application-specific sanity checks throughout the system.


NEW QUESTION # 150
DRAG DROP
A number of security design patterns are developed for software assurance in general. Drag and drop the appropriate security design patterns in front of their respective descriptions.

Answer:

Explanation:

Explanation:

The various patterns applicable to software assurance in general are as follows: Hidden implementation: It limits the ability of an attacker to distinguish the internal workings of an application. Partitioned application: It splits a large and complex application into two or more simple components. Secure assertion: It distributes application-specific sanity checks throughout the system. Server sandbox: It creates a wall around the Web server to include the damage that occurs because of an undetected fault in the server or an exploited vulnerability.


NEW QUESTION # 151
Which of the following documents is defined as a source document, which is most useful for the ISSE when classifying the needed security functionality?

  • A. IMM
  • B. CONOPS
  • C. System Security Context
  • D. Information Protection Policy (IPP)

Answer: D

Explanation:
The Information Protection Policy (IPP) is defined as a source document, which is most useful for the ISSE when classifying the needed security functionality. The IPP document consists of the threats to the information management and the security services and controls needed to respond to those threats. Answer B is incorrect. The IMM is the source document describing the customer's needs based on identifying users, processes, and information. Answer C is incorrect. The System Security Context is the output of SE and ISSEP. It is the translation of the requirements into system parameters and possible measurement concepts that meet the defined requirements. Answer D is incorrect. The Concept of Operations (CONOPS) is a document describing the characteristics of a proposed system from the viewpoint of an individual who will use that system. It is used to communicate the quantitative and qualitative system characteristics to all stakeholders. CONOPS are widely used in the military or in government services, as well as other fields. A CONOPS generally evolves from a concept and is a description of how a set of capabilities may be employed to achieve desired objectives or a particular end state for a specific scenario.


NEW QUESTION # 152
Which of the following are the types of access controls? Each correct answer represents a complete solution. Choose three.

  • A. Administrative
  • B. Technical
  • C. Automatic
  • D. Physical

Answer: A,B,D

Explanation:
Security guards, locks on the gates, and alarms come under physical access control. Policies and procedures implemented by an organization come under administrative access control. IDS systems, encryption, network segmentation, and antivirus controls come under technical access control. Answer D is incorrect. There is no such type of access control as automatic control.


NEW QUESTION # 153
Bill is the project manager of the JKH Project. He and the project team have identified a risk event in the project with a high probability of occurrence and the risk event has a high cost impact on the project. Bill discusses the risk event with Virginia, the primary project customer, and she decides that the requirements surrounding the risk event should be removed from the project. The removal of the requirements does affect the project scope, but it can release the project from the high risk exposure. What risk response has been enacted in this project?

  • A. Transference
  • B. Acceptance
  • C. Avoidance
  • D. Mitigation

Answer: C

Explanation:
Explanation/Reference:
Explanation: This is an example of the avoidance risk response. Because the project plan has been changed to avoid the risk event, so it is considered the avoidance risk response. Risk avoidance is a technique used for threats. It creates changes to the project management plan that are meant to either eliminate the risk completely or to protect the project objectives from its impact. Risk avoidance removes the risk event entirely either by adding additional steps to avoid the event or reducing the project scope requirements. It may seem the answer to all possible risks, but avoiding risks also means losing out on the potential gains that accepting (retaining) the risk might have allowed. Answer: C is incorrect. Acceptance is when the stakeholders acknowledge the risk event and they accept that the event could happen and could have an impact on the project. Acceptance is usually used for risk events that have low risk exposure or risk events in which the project has no control, such as a pending law or weather threats. Answer: A is incorrect. Mitigation is involved with the actions to reduce an included risk's probability and/or impact on the project's objectives. As the risk was removed from the project, this scenario describes avoidance, not mitigation. Answer: B is incorrect. Transference is when the risk is still within the project, but the ownership and management of the risk event is transferred to a third party - usually for a fee.


NEW QUESTION # 154
Which of the following types of activities can be audited for security? Each correct answer represents a complete solution. Choose three.

  • A. Printer access
  • B. File and object access
  • C. Data downloading from the Internet
  • D. Network logons and logoffs

Answer: A,B,D

Explanation:
Explanation/Reference:
Explanation: The following types of activities can be audited: Network logons and logoffs File access Printer access Remote access service Application usage Network services Auditing is used to track user accounts for file and object access, logon attempts, system shutdown, etc. This enhances the security of the network. Before enabling security auditing, the type of event to be audited should be specified in the audit policy. Auditing is an essential component to maintain the security of deployed systems. Security auditing depends on the criticality of the environment and on the company's security policy. The security system should be reviewed periodically. Answer: B is incorrect. Data downloading from the Internet cannot be audited.


NEW QUESTION # 155
You work as a security manager for BlueWell Inc. You are going through the NIST SP 800-37 C&A methodology, which is based on four well defined phases. In which of the following phases of NIST SP 800-37 C&A methodology does the security categorization occur?

  • A. Security Accreditation
  • B. Security Certification
  • C. Initiation
  • D. Continuous Monitoring

Answer: C

Explanation:
The various phases of NIST SP 800-37 C&A are as follows: Phase 1: Initiation- This phase includes preparation, notification and resource identification. It performs the security plan analysis, update, and acceptance. Phase 2: Security Certification- The Security certification phase evaluates the controls and documentation. Phase 3: Security Accreditation- The security accreditation phase examines the residual risk for acceptability, and prepares the final security accreditation package. Phase 4: Continuous Monitoring-This phase monitors the configuration management and control, ongoing security control verification, and status reporting and documentation.


NEW QUESTION # 156
FIPS 199 defines the three levels of potential impact on organizations: low, moderate, and high. Which of the following are the effects of loss of confidentiality, integrity, or availability in a high level potential impact?

  • A. The loss of confidentiality, integrity, or availability might cause severe degradation in or loss of mission capability to an extent.
  • B. The loss of confidentiality, integrity, or availability might result in major financial losses.
  • C. The loss of confidentiality, integrity, or availability might result in severe damages like life threatening injuries or loss of life.
  • D. The loss of confidentiality, integrity, or availability might result in a major damage to organizational assets.

Answer: A,B,C,D

Explanation:
The following are the effects of loss of confidentiality, integrity, or availability in a high level potential impact: It might cause a severe degradation in or loss of mission capability to an extent. It might result in a major damage to organizational assets. It might result in a major financial loss. It might result in severe harms such as serious life threatening injuries or loss of life.


NEW QUESTION # 157
Which of the following are the responsibilities of a custodian with regard to data in an information classification program? Each correct answer represents a complete solution. Choose three.

  • A. Determining what level of classification the information requires
  • B. Performing data restoration from the backups when necessary
  • C. Controlling access, adding and removing privileges for individual users
  • D. Running regular backups and routinely testing the validity of the backup data

Answer: B,C,D

Explanation:
The owner of information delegates the responsibility of protecting that information to a custodian. The following are the responsibilities of a custodian with regard to data in an information classification program: Running regular backups and routinely testing the validity of the backup data Performing data restoration from the backups when necessary Controlling access, adding and removing privileges for individual users Answer C is incorrect. Determining what level of classification the information requires is the responsibility of the owner.


NEW QUESTION # 158
There are seven risks responses that a project manager can choose from. Which risk response is appropriate for both positive and negative risk events?

  • A. Transference
  • B. Acceptance
  • C. Sharing
  • D. Mitigation

Answer: B

Explanation:
Explanation/Reference:
Explanation: Only acceptance is appropriate for both positive and negative risk events. Often sharing is used for low probability and low impact risk events regardless of the positive or negative effects the risk event may bring the project. Acceptance response is a part of Risk Response planning process.
Acceptance response delineates that the project plan will not be changed to deal with the risk.
Management may develop a contingency plan if the risk does occur. Acceptance response to a risk event is a strategy that can be used for risks that pose either threats or opportunities. Acceptance response can be of two types: Passive acceptance: It is a strategy in which no plans are made to try or avoid or mitigate the risk. Active acceptance: Such responses include developing contingency reserves to deal with risks, in case they occur. Acceptance is the only response for both threats and opportunities. Answer: C is incorrect. Sharing is a positive risk response that shares an opportunity for all parties involved in the risk event. Answer: B is incorrect. Transference is a negative risk event that transfers the risk ownership to a third party, such as vendor, through a contractual relationship. Answer: D is incorrect. Mitigation is a negative risk event that seeks to lower the probability and/or impact of a risk event.


NEW QUESTION # 159
What are the differences between managed and unmanaged code technologies? Each correct answer represents a complete solution. Choose two.

  • A. Managed code is compiled into an intermediate code format, whereas unmanaged code is compiled into machine code.
  • B. C and C++ are the examples of managed code, whereas Java EE and Microsoft.NET are the examples of unmanaged code.
  • C. Managed code executes under management of a runtime environment, whereas unmanaged code is executed by the CPU of a computer system.
  • D. Managed code is referred to as Hex code, whereas unmanaged code is referred to as byte code.

Answer: A,C

Explanation:
Programming languages are categorized into two technologies: 1.Managed code: This computer program code is compiled into an intermediate code format. Managed code is referred to as byte code. It executes under the management of a runtime environment. Java EE and Microsoft.NET are the examples of managed code. 2.Unmanaged code: This computer code is compiled into machine code. Unmanaged code is executed by the CPU of a computer system. C and C++ are the examples of unmanaged code. Answer A is incorrect. Managed code is referred to as byte code. Answer B is incorrect. C and C++ are the examples of unmanaged code, whereas Java EE and Microsoft.NET are the examples of managed code.


NEW QUESTION # 160
You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used for computer system management and security auditing, as well as for generalized informational, analysis, and debugging messages. You want to prevent a denial of service (DoS) for the Syslog server and the loss of Syslog messages from other sources. What will you do to accomplish the task?

  • A. Use a different message format other than Syslog in order to accept data.
  • B. Encrypt rotated log files automatically using third-party or OS mechanisms.
  • C. Limit the number of Syslog messages or TCP connections from a specific source for a certain time period.
  • D. Enable the storage of log entries in both traditional Syslog files and a database.

Answer: C

Explanation:
In order to accomplish the task, you should limit the number of Syslog messages or TCP connections from a specific source for a certain time period. This will prevent a denial of service (DoS) for the Syslog server and the loss of Syslog messages from other sources. Answer D is incorrect. You can encrypt rotated log files automatically using third-party or OS mechanisms to protect data confidentiality. Answer A is incorrect. You can use a different message format other than Syslog in order to accept data for aggregating data from hosts that do not support Syslog. Answer B is incorrect. You can enable the storage of log entries in both traditional Syslog files and a database for creating a database storage for logs.


NEW QUESTION # 161
The mission and business process level is the Tier 2. What are the various Tier 2 activities? Each correct answer represents a complete solution. Choose all that apply.

  • A. Defining the types of information that the organization needs, to successfully execute the stated missions and business processes
  • B. Prioritizing missions and business processes with respect to the goals and objectives of the organization
  • C. Specifying the degree of autonomy for the subordinate organizations
  • D. Developing an organization-wide information protection strategy and incorporating high-level information security requirements
  • E. Defining the core missions and business processes for the organization

Answer: A,B,C,D,E

Explanation:
Explanation/Reference:
Explanation: The mission and business process level is the Tier 2. It addresses risks from the mission and business process perspective. It is guided by the risk decisions at Tier 1. The various Tier 2 activities are as follows: It defines the core missions and business processes for the organization. It also prioritizes missions and business processes, with respect to the goals and objectives of the organization. It defines the types of information that an organization requires, to successfully execute the stated missions and business processes. It helps in developing an organization-wide information protection strategy and incorporating high-level information security requirements. It specifies the degree of autonomy for the subordinate organizations.


NEW QUESTION # 162
Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?

  • A. SSAA
  • B. DIACAP
  • C. ISSO
  • D. DAA

Answer: B

Explanation:
Explanation/Reference:
Explanation: DIACAP describes a residual risk as the risk remaining after a risk mitigation has occurred.
The Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) is a process defined by the United States Department of Defense (DoD) for managing risk. DIACAP replaced the former process, known as DITSCAP (Department of Defense Information Technology Security Certification and Accreditation Process), in 2006. DoD Instruction (DoDI) 8510.01 establishes a standard DoD-wide process with a set of activities, general tasks, and a management structure to certify and accredit an Automated Information System (AIS) that will maintain the Information Assurance (IA) posture of the Defense Information Infrastructure (DII) throughout the system's life cycle.DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. It identifies four phases: 1.System Definition
2.Verification 3.Validation 4.Re-Accreditation AnswerD is incorrect. An Information System Security Officer (ISSO) plays the role of a supporter. The responsibilities of an Information System Security Officer (ISSO) are as follows: Manages the security of the information system that is slated for Certification & Accreditation (C&A). Insures the information systems configuration with the agency's information security policy. Supports the information system owner/information owner for the completion of security-related responsibilities. Takes part in the formal configuration management process. Prepares Certification & Accreditation (C&A) packages. AnswerC is incorrect. The Designated Approving Authority (DAA), in the United States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. The DAA is responsible for implementing system security. The DAA can grant the accreditation and can determine that the system's risks are not at an acceptable level and the system is not ready to be operational. AnswerB is incorrect. System Security Authorization Agreement (SSAA) is an information security document used in the United States Department of Defense (DoD) to describe and accredit networks and systems. The SSAA is part of the Department of Defense Information Technology Security Certification and Accreditation Process, or DITSCAP (superseded by DIACAP). The DoD instruction (issues in December 1997, that describes DITSCAP and provides an outline for the SSAA document is DODI 5200.40. The DITSCAP application manual (DoD 8510.1-M), published in July 2000, provides additional details.


NEW QUESTION # 163
......

Pass ISC CSSLP Premium Files Test Engine pdf - Free Dumps Collection: https://www.crampdf.com/CSSLP-exam-prep-dumps.html

New 2023 Realistic CSSLP Dumps Test Engine Exam Questions in here: https://drive.google.com/open?id=1pMPjnnTgOLyogW4URKTeQz0tuVDJepGU