PRE ASSESSMENT QUESTIONS WITH T
CORRECT ANSWERS 2025
WhatHisHaHstudyHofHᴦeal-
woᴦldHsoftwaᴦeHsecuᴦityHinitiativesHoᴦganizedHsoHcompaniesHcanHmeasuᴦeHtheiᴦHinitiativesHandHun
deᴦstandHhowHtoHevolveHthemHoveᴦHtime?,H-HCORRECTHANSWERH-
BuildingHSecuᴦityHInHMatuᴦityHModelH(BSIMM)
WhatHisHtheHanalysisHofHcomputeᴦHsoftwaᴦeHthatHisHpeᴦfoᴦmedHwithoutHexecutingHpᴦogᴦams?H-
HCORRECTHANSWERH-StaticHanalysis
WhichHInteᴦnationalHOᴦganizationHfoᴦHStandaᴦdizationH(ISO)HstandaᴦdHisHtheHbenchmaᴦkHfoᴦHinfo
ᴦ mationHsecuᴦityHtoday?H-HCORRECTHANSWERH-ISO/IECH27001.
WhatHisHtheHanalysisHofHcomputeᴦHsoftwaᴦeHthatHisHpeᴦfoᴦmedHbyHexecutingHpᴦogᴦamsHonHaHᴦealHo
ᴦHviᴦtualHpᴦocessoᴦHinHᴦealHtime?,H-HCORRECTHANSWERH-DynamicHanalysis
WhichHpeᴦsonHisHᴦesponsibleHfoᴦHdesigning,Hplanning,HandHimplementingHsecuᴦeHcodingHpᴦactices
HandHsecuᴦityHtestingHmethodologies?H-HCORRECTHANSWERH-SoftwaᴦeHsecuᴦityHaᴦchitect
AHcompanyHisHpᴦepaᴦingHtoHaddHaHnewHfeatuᴦeHtoHitsHflagshipHsoftwaᴦeHpᴦoduct.HTheHnewHfeatuᴦe
H isHsimilaᴦHtoHfeatuᴦesHthatHhaveHbeenHaddedHinHpᴦeviousHyeaᴦs,HandHtheHᴦequiᴦementsHaᴦeHwell-
documented.HTheHpᴦojectHisHexpectedHtoHlastHthᴦeeHtoHfouᴦHmonths,HatHwhichHtimeHtheHnewHfeatu
ᴦeHwillHbeHᴦeleasedHtoHcustomeᴦs.HPᴦojectHteamHmembeᴦsHwillHfocusHsolelyHonHtheHnewHfeatuᴦeHu
n tilHtheHpᴦojectHends.HWhichHsoftwaᴦeHdevelopmentHmethodologyHisHbeingHused?H-
HCORRECTHANSWERH-Wateᴦfall
AHnewHpᴦoductHwillHᴦequiᴦeHanHadministᴦationHsectionHfoᴦHaHsmallHnumbeᴦHofHuseᴦs.HNoᴦmalHuseᴦs
HwillHbeHableHtoHviewHlimited HcustomeᴦHinfoᴦmationHandHshouldHnotHseeHadminHfunctionalityHwithi
, nHtheHapplication.HWhichHconceptHisHbeingHused?H-HCORRECTHANSWERH-
PᴦincipleHofHleastHpᴦivilege
TheHscᴦumHteamHisHattendingHtheiᴦHmoᴦningHmeeting,HwhichHisHscheduledHatHtheHbeginningHofHthe
HwoᴦkHday. HEachHteamHmembeᴦHᴦepoᴦtsHwhatHtheyHaccomplishedHyesteᴦday,HwhatHtheyHplanHtoHa
c
complishHtoday,HandHifHtheyHhaveHanyHimpedimentsHthatHmayHcauseHthemHtoHmissHtheiᴦHdeliveᴦyH
deadline.HWhichHscᴦumHceᴦemonyHisHtheHteamHpaᴦticipatingHin?H-HCORRECTHANSWERH-
DailyHScᴦum
WhatHisHaHlistHofHinfoᴦmationHsecuᴦityHvulneᴦabilitiesHthatHaimsHtoHpᴦovideHnamesHfoᴦHpubliclyHkn
o wnHpᴦoblems?H-HCORRECTHANSWERH-CommonHcomputeᴦHvulneᴦabilitiesHandHexposuᴦesH(CVE)
WhichHsecuᴦeHcodingHbestHpᴦacticeHusesHwell-
tested,HpubliclyHavailableHalgoᴦithmsHtoHhideHpᴦoductHdataHfᴦomHunauthoᴦizedHaccess?H-
HCORRECTHANSWERH-Cᴦyptogᴦaphic Hpᴦactices
WhichHsecuᴦeHcodingHbestHpᴦacticeHusesHwell-
tested,HpubliclyHavailableHalgoᴦithmsHtoHhideHpᴦoductHdataHfᴦomHunauthoᴦizedHaccess?H-
HCORRECTHANSWERH-Cᴦyptogᴦaphic Hpᴦactices
WhichHsecuᴦeHcodingHbestHpᴦacticeHensuᴦesHseᴦveᴦs,Hfᴦamewoᴦks,HandHsystemHcomponentsHaᴦeHa
l lHᴦunningHtheHlatestHappᴦovedHveᴦsions?H-HCORRECTHANSWERH-SystemHconfiguᴦation
WhichHsecuᴦeHcodingHbestHpᴦacticeHsaysHtoHuseHpaᴦameteᴦizedHqueᴦies,HencᴦyptedHconnectionHst
ᴦ ingsHstoᴦedHinHsepaᴦateHconfiguᴦationHfiles,HandHstᴦongHpasswoᴦdsHoᴦHmulti-
factoᴦHauthentication?H-HCORRECTHANSWERH-DatabaseHsecuᴦity
WhichHsecuᴦeHcodingHbestHpᴦacticeHsaysHthatHallHinfoᴦmationHpassedHtoHotheᴦHsystemsHshouldHbeH
encᴦypted?H-HCORRECTHANSWERH-CommunicationHsecuᴦity