Actual Final Exam Questions With Reviewed 100%
Correct Detailed Answers
Guaranteed Pass!!Current Update
1. What is BSIMM? - ANSWER Building Security in Maturity Model - study
of real world soft security initatives organized so you can determine where
you stand with your soft sec
2. What are the 6 steps in SDLC? - ANSWER 1. Analysis
2. Design
3. Development
4. Testing
5. Deployment
6. Maintenance
3. What is SAMM? - ANSWER offers a roadmap and maturity model for
secure soft devel and deployment, with self-assessment and planning
4. What are core OpenSAMM activities? - ANSWER Governance
Construction
Verification
, Deployment
5. What is static versus dyamic analysis? - ANSWER static - source code
reviewed manually and WITHOUT running code
6. dynamic - analysis occurs WHILE being run or executed
7. What is fuzzing? - ANSWER injecting random data into soft program to
find errors
8. What is ISO/IEC 27001? - ANSWER specifies requirements for
establishing, implementing, monitoring, etc. a documented info sec mana
sys
9. What is ISO/IEC 17799? - ANSWER defines CIA controls
10.What is ISO/IEC 27034? - ANSWER helps organiz embed sec within their
processes including app lifecycle processes
11.What is a software security champion? - ANSWER A developer with
interest in security who helps amplify the security message at the team
level
12.What is waterfall methodology? - ANSWER a sequential, activity-based
process in which one phase of the SDLC is followed by another