

Secure Software Development Exam
Solutions
Course Introduction
Secure Software Development explores methodologies and best practices for designing, building, and maintaining software with strong security foundations. The course covers topics such as secure coding principles, threat modeling, vulnerability assessment, cryptography in applications, and secure software development lifecycle (SSDLC). Students will learn how to identify and mitigate common software vulnerabilities, integrate security into agile and DevOps workflows, and comply with legal and regulatory standards. Through hands-on projects and real-world case studies, learners gain practical skills for developing robust, resilient applications that withstand modern cyber threats.
Recommended Textbook
Computer Security Principles and Practice 2nd Edition by William Stallings
Available Study Resources on Quizplus
24 Chapters
1078 Verified Questions
1078 Flashcards
Source URL: https://quizplus.com/study-set/3971

Page 2

Chapter 1: Computer Systems Overview
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79799
Sample Questions
Q1) Masquerade,falsification,and repudiation are threat actions that cause __________ threat consequences.
A)unauthorized disclosure
B)disruption
C)deception
D)usurpation
Answer: C
Q2) The OSI security architecture focuses on security attacks,__________,and services.
Answer: mechanisms
Q3) An example of __________ is an attempt by an unauthorized user to gain access to a system by posing as an authorized user.
A)masquerade
B)repudiation
C)interception
D)inference
Answer: A
Q4) Misappropriation and misuse are attacks that result in ________ threat consequences.
Answer: usurpation
To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Cryptographic Tools
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79788
Sample Questions
Q1) There are two general approaches to attacking a symmetric encryption scheme: cryptanalytic attacks and __________ attacks.
Answer: brute-force
Q2) The purpose of the DSS algorithm is to enable two users to securely reach agreement about a shared secret that can be used as a secret key for subsequent symmetric encryption of messages.
A)True
B)False
Answer: False
Q3) Like the MAC,a hash function also takes a secret key as input.
A)True
B)False
Answer: False
Q4) A __________ processes the plaintext input in fixed-size blocks and produces a block of ciphertext of equal size for each plaintext block.
Answer: block cipher
Q5) The two criteria used to validate that a sequence of numbers is random are independence and _________ .
Answer: uniform distribution
To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: User Authentication
Available Study Resources on Quizplus for this Chatper
44 Verified Questions
44 Flashcards
Source URL: https://quizplus.com/quiz/79782
Sample Questions
Q1) A token is the best means of authentication because it cannot be forged or stolen by an adversary.
A)True
B)False
Answer: False
Q2) Voice pattern,handwriting characteristics,and typing rhythm are examples of __________ biometrics.
Answer: dynamic
Q3) A __________ attack involves an adversary repeating a previously captured user response.
A)client
B)Trojan horse
C)replay
D)eavesdropping
Answer: C
Q4) In a __________ attack,an application or physical device masquerades as an authentic application or device for the purpose of capturing a user password,passcode,or biometric.
Answer: Trojan horse
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Access Control
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79781
Sample Questions
Q1) Role hierarchies make use of the concept of __________ to enable one role to implicitly include access rights associated with a subordinate role.
Q2) __________ provide a means of adapting RBAC to the specifics of administrative and security policies in an organization.
A)Constraints
B)Mutually Exclusive Roles
C)Cardinality
D)Prerequisites
Q3) T F 4.External devices such as firewalls cannot provide access control services.
A)True
B)False
Q4) The main innovation of the NIST standard is the introduction of the RBAC System and Administrative Functional Specification,which defines the features required for an RBAC system.
A)True
B)False
Q5) The authentication function determines who is trusted for a given purpose.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Database Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79780
Sample Questions
Q1) A __________ is a suite of programs for constructing and maintaining the database and for offering ad hoc query facilities to multiple users and applications.
Q2) To create a relationship between two tables,the attributes that define the primary key in one table must appear as attributes in another table,where they are referred to as a foreign key.
A)True
B)False
Q3) The _________ model provides a predefined environment for the cloud subscriber that is shared with other tenants,typically through tagging data with a subscriber identifier.
Q4) _________ is a model for enabling ubiquitous,convenient,on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.
Q5) With ___________ administration the owner (creator)of a table may grant and revoke access rights to the table.
Q6) The __________ is a human entity that presents requests (queries)to the system.
Q7) In a relational database columns are referred to as _________.
Page 7
To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Malicious Software
Available Study Resources on Quizplus for this Chatper
44 Verified Questions
44 Flashcards
Source URL: https://quizplus.com/quiz/79779
Sample Questions
Q1) The __________ is when the virus function is performed.
A)dormant phase
B)propagation phase
C)triggering phase
D)execution phase
Q2) A bot can use a __________ to capture keystrokes on the infected machine to retrieve sensitive information.
Q3) Keyware captures keystrokes on a compromised system.
A)True
B)False
Q4) A __________ is when a user views a Web page controlled by the attacker that contains a code that exploits the browser bug and downloads and installs malware on the system without the user's knowledge or consent.
Q5) During the __________ phase the virus is activated to perform the function for which it was intended.
Q6) A bot propagates itself and activates itself,whereas a worm is initially controlled from some central facility.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Denial-Of-Service Attacks
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79778
Sample Questions
Q1) A ______ triggers a bug in the system's network handling software causing it to crash and the system can no longer communicate over the network until this software is reloaded.
A)echo
B)reflection
C)poison packet
D)flash flood
Q2) Slowloris is a form of ICMP flooding.
A)True
B)False
Q3) Reflector and amplifier attacks use compromised systems running the attacker's programs.
A)True
B)False
Q4) A _____ is an action that prevents or impairs the authorized use of networks,systems,or applications by exhausting resources such as central processing units,memory,bandwidth,and disk space.
Q5) _____ attacks flood the network link to the server with a torrent of malicious packets competing with valid traffic flowing to the server.
To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Intrusion Detection
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79777
Sample Questions
Q1) Signature-based approaches attempt to define normal,or expected, behavior,whereas anomaly approaches attempt to define proper behavior.
A)True
B)False
Q2) The rule _______ tells Snort what to do when it finds a packet that matches the rule criteria.
A)protocol
B)direction
C)action
D)destination port
Q3) The purpose of the ________ module is to collect data on security related events on the host and transmit these to the central manager.
A)central manager agent
B)LAN monitor agent
C)host agent
D)architecture agent
Q4) An intruder can also be referred to as a hacker or cracker.
A)True
B)False
Q5) An IDS comprises three logical components: analyzers,user interface and _____.
Page 10
To view all questions and flashcards with answers, click on the resource link above.

Chapter 9: Firewalls and Intrusion Prevention Systems
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79776
Sample Questions
Q1) An intruder transmitting packets from the outside with a source IP address field containing an address of an internal host is known as IP address _________.
Q2) An important aspect of a distributed firewall configuration is security monitoring.
A)True
B)False
Q3) One disadvantage of a packet filtering firewall is its simplicity.
A)True
B)False
Q4) __________ scans for attack signatures in the context of a traffic stream rather than individual packets.
A)Pattern matching
B)Protocol anomaly
C)Traffic anomaly
D)Stateful matching
Q5) A single device that integrates a variety of approaches to dealing with network-based attacks is referred to as a __________ system.
Q6) Snort Inline adds three new rule types: drop,reject,and _________.
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Buffer Overflow
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79798
Sample Questions
Q1) The only consequence of a buffer overflow attack is the possible corruption of data used by the program.
A)True
B)False
Q2) _______ defenses aim to detect and abort attacking existing programs.
Q3) _______ defenses involve changes to the memory management of the virtual address space of processes that act to either alter the properties of regions of memory or to make predicting the location of target buffers sufficiently difficult to thwart many types of attacks.
A)Buffer
B)Position independent
C)Run-time
D)Compile-time
Q4) The _________ project produces a free,multiplatform 4.4BSD-based UNIX-like operating system.
Q5) ________ attacks can occur in a binary buffer copy when the programmer has included code to check the number of bytes being transferred,but due to a coding error,allows just one more byte to be copied than there is space available.
Q6) ______ defenses aim to harden programs to resist attacks in new programs.
Page 12
To view all questions and flashcards with answers, click on the resource link above.

Chapter 11: Software Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79797
Sample Questions
Q1) "Failure to Preserve SQL Query Structure" is in the __________ CWE/SANS software error category.
Q2) Two key areas of concern for any input are the _______ of the input and the meaning and interpretation of the input.
Q3) If privileges are greater than those already available to the attacker the result is a _________.
Q4) The most common technique for using an appropriate synchronization mechanism to serialize the accesses to prevent errors is to acquire a _______ on the shared file,ensuring that each process has appropriate access in turn.
A)lock
B)code injection
C)chroot jail
D)privilege escalation
Q5) _________ attacks are most commonly seen in scripted Web applications.
Q6) The correct implementation in the case of an atomic operation is to test separately for the presence of the lockfile and to not always attempt to create it.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Operating System Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79796
Sample Questions
Q1) The aim of the specific system installation planning process is to maximize _______ while minimizing costs.
Q2) A malicious driver can potentially bypass many security controls to install malware.
A)True
B)False
Q3) ______ virtualization systems are typically seen in servers,with the goal of improving the execution efficiency of the hardware.
Q4) Backup and archive processes are often linked and managed together. A)True
B)False
Q5) Unix and Linux systems grant access permissions for each resource using the ______ command.
Q6) Performing regular backups of data on a system is a critical control that assists with maintaining the integrity of the system and user data.
A)True B)False
Q7) The three operating system security layers are: physical hardware,operating system kernel,and _________.
To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Trusted Computing and Multilevel Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79795
Sample Questions
Q1) A multilevel secure system for confidentiality must enforce:
A)no read up
B)ss-property
C)no write down
D)all of the above
Q2) "An individual (or role)may grant to another individual (or role)access to a document based on the owner's discretion,constrained by the MAC rules" describes the
A)ss-property
B)ds-property
C)*-property
D)cc-property
Q3) Security classes are referred to as __________.
A)security clearances
B)security classifications
C)security levels
D)security properties
Q4) To structure the need for assurance the CC defines a scale for rating assurance consisting of _____ evaluation assurance levels ranging from the least rigor and scope for assurance evidence to the most.
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: It Security Management and Risk Assessment
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79794
Sample Questions
Q1) Maintaining and improving the information security risk management process in response to incidents is part of the _________ step.
A)act
B)plan
C)check
D)do
Q2) The purpose of ________ is to determine the basic parameters within which the risk assessment will be conducted and then to identify the assets to be examined.
A)establishing the context
B)control
C)risk avoidance
D)combining
Q3) It is not critical that an organization's IT security policy have full approval or buy-in by senior management.
A)True
B)False
Q4) Not proceeding with the activity or system that creates the risk is _________.
Q5) The level of risk the organization views as acceptable is the organization's
To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: It Security Controls, plans, and Procedures
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79793
Sample Questions
Q1) The objective of the ________ control category is to counteract interruptions to business activities and to protect critical business processes from the effects of major failures of information systems or disasters and to ensure their timely resumption.
A)asset management
B)business continuity management
C)information security incident management
D)physical and environmental security
Q2) _________ is a formal process to ensure that critical assets are sufficiently protected in a cost-effective manner.
A)Configuration management control
B)IT security management
C)Detection and recovery control
D)Security compliance
Q3) The recommended controls need to be compatible with the organization's systems and policies.
A)True
B)False
Q4) ______ checking is an audit process to review the organization's security processes.
To view all questions and flashcards with answers, click on the resource link above. Page 17

Chapter 16: Physical and Infrastructure Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79792
Sample Questions
Q1) Physical security must also prevent any type of physical access or intrusion that can compromise logical security.
A)True
B)False
Q2) The security classification for a restricted area containing a security interest is _____.
A)controlled
B)exclusion
C)unrestricted
D)limited
Q3) _______ facilities include electrical power,communication services,and environmental controls such as heat and humidity.
A)Supporting
B)Information
C)Physical
D)All of the above
Q4) _______ threats encompass threats related to electrical power and electromagnetic emission.
Q5) The most essential element of recovery from physical security breaches is ____.
To view all questions and flashcards with answers, click on the resource link above. Page 18

Chapter 17: Human Resources Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79791
Sample Questions
Q1) A(n)________ is any file or object found on a system that might be involved in probing or attacking systems and networks or that is being used to defeat security measures.
Q2) The principal problems associated with employee behavior are errors and omissions,_______,and actions by disgruntled employees.
Q3) Having all of the security functions and audit responsibilities reside in the same person is a wise decision on the part of the organization.
A)True B)False
Q4) ________ lists the following security objective with respect to current employees: to ensure that employees,contractors,and third-party users are aware of information security threats and concerns and their responsibilities and liabilities with regard to information security and are equipped to support organizational security policy in the course of their normal work and to reduce the risk of human error.
Q5) Complying with regulations and contractual obligations is a benefit of security awareness,training,and education programs.
A)True B)False
To view all questions and flashcards with answers, click on the resource link above. Page 19

Chapter 18: Security Auditing
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79790
Sample Questions
Q1) _________ audit trails are generally used to monitor and optimize system performance.
A)User-level
B)Physical-level
C)System-level
D)All of the above
Q2) ______ is detection of events within a given set of parameters,such as within a given time period or outside a given time period.
Q3) The basic audit objective is to establish accountability for system entities that initiate or participate in security-relevant events and actions.
A)True
B)False
Q4) ______ is the identification of data that exceed a particular baseline value.
A)Anomaly detection
B)Real-time analysis
C)Thresholding
D)All of the above
Q5) Protection of the audit trail involves both integrity and confidentiality.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 20

Chapter 19: Legal and Ethical Aspects
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79789
Sample Questions
Q1) An example of a patent from the computer security realm is the RSA public-key cryptosystem.
A)True
B)False
Q2) _______ refers to a system of moral principles that relates to the benefits and harms of particular actions,and to the rightness and wrongness of motives and ends of those actions.
Q3) _____ can be copyrighted.
A)Dramatic works
B)Architectural works
C)Software-related works
D)All of the above
Q4) _____ strengthens the protection of copyrighted materials in digital format.
A)HIPPA
B)DMCA
C)WIPO
D)DRM
Q5) The _________ Act confers certain rights on individuals and obligations on credit reporting agencies.
Page 21
Q6) The three types of patents are: utility patents,design patents,and ________.
To view all questions and flashcards with answers, click on the resource link above.

Chapter 20: Symmetric Encryption and Message
Confidentiality
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79787
Sample Questions
Q1) Unlike ECB and CBC modes,________ mode requires only the implementation of the encryption algorithm and not the decryption algorithm.
Q2) _________ is the process of attempting to discover the plaintext or key.
Q3) "The plaintext is 64 bits in length and the key is 56 bits in length; longer plaintext amounts are processed in 64-bit blocks" is a description of the DES algorithm.
A)True
B)False
Q4) An encryption scheme is _________ if the cost of breaking the cipher exceeds the value of the encrypted information and/or the time required to break the cipher exceeds the useful lifetime of the information.
Q5) The _______ module performs end-to-end encryption and obtains session keys on behalf of users.
A)PKM
B)RCM
C)SSM
D)CCM
Q6) The three most important symmetric block ciphers are: 3DES,AES,and _____.
Page 22
To view all questions and flashcards with answers, click on the resource link above.

Chapter 21: Public-Key Cryptography and Message
Authentication
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79786
Sample Questions
Q1) NIST has published FIPS PUB 186,which is known as the ___________.
Q2) SHA-2 shares the same structure and mathematical operations as its predecessors and this is a cause for concern.
A)True
B)False
Q3) The key exchange protocol is vulnerable to a man-in-the-middle attack because it does not authenticate the participants.
A)True
B)False
Q4) The evaluation criteria for the new hash function are: security,_______,and algorithm and implementation characteristics.
Q5) SHA-3 algorithms must be designed to resist any potentially successful attack on SHA-2 functions.
A)True
B)False
Q6) One of the first public-key schemes,_______,was developed in 1977 by Ron Rivest,Adi Shamir,and Len Adleman.
Q8) One of the simplest hash functions is the ________ of every block. Page 23
Q7) Perhaps the most widely used public-key algorithms are _________ and Diffie-Hellman.
To view all questions and flashcards with answers, click on the resource link above.
Page 24

Chapter 22: Internet Security Protocols and Standards
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79785
Sample Questions
Q1) _______ is a list that contains the combinations of cryptographic algorithms supported by the client.
A)Compression method
B)Session ID
C)CipherSuite
D)All of the above
Q2) The ________ accepts the message submitted by a message user agent and enforces the policies of the hosting domain and the requirements of Internet standards.
A)mail submission agent
B)message user agent
C)mail delivery agent
D)message transfer agent
Q3) At its most fundamental level the Internet mail architecture consists of a user world in the form of _________.
A)MHS
B)MSA
C)MUA
D)MDA
Q4) The _________ is used to convey SSL-related alerts to the peer entity.
To view all questions and flashcards with answers, click on the resource link above. Page 25

Chapter 23: Internet Authentication Applications
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79784
Sample Questions
Q1) The principal objective for developing a PKI is to enable secure, convenient,and efficient acquisition of private keys.
A)True
B)False
Q2) An obvious security risk is that of impersonation.
A)True
B)False
Q3) _______ is the process whereby a user first makes itself known to a CA prior to that CA issuing a certificate or certificates for that user.
A)Authorization
B)Registration
C)Certification
D)Initialization
Q4) ________ allows end entities to restore their encryption/decryption key pair from an authorized key backup facility.
Q5) In a generic identity management architecture a ________ is an identity holder.
Q6) The focus of _________ is defining an identity for each user,associating attributes with the identity,and enforcing a means by which a user can verify identity.
To view all questions and flashcards with answers, click on the resource link above. Page 26

Chapter 24: Wireless Network Security
Available Study Resources on Quizplus for this Chatper
45 Verified Questions
45 Flashcards
Source URL: https://quizplus.com/quiz/79783
Sample Questions
Q1) A system used to interconnect a set of basic service sets and LANs to create an extended service set is a _________.
A)distribution system
B)coordination function
C)MAC data unit
D)wireless access system
Q2) In order to accelerate the introduction of strong security into WLANs the Wi-Fi Alliance promulgated ________,a set of security mechanisms that eliminates most 802.11 security issues,as a Wi-Fi standard.
A)WPA
B)WEP
C)RSN
D)MAC
Q3) CRC is an error detecting code.
A)True
B)False
Q4) The fields preceding the MSDU field are referred to as the _________.
Q5) The lowest layer of the IEEE 802 reference model is the __________ layer.
Q6) Like TKIP,CCMP provides two services: message integrity and ________.
Q7) At the top level of the group key hierarchy is the ___________.
To view all questions and flashcards with answers, click on the resource link above. Page 27