試験科目:Certified Secure Software Lifecycle Professional Practice Test
問題と解答:全349問 CSSLP 認証資格

NO.1 Part of your change management plan details what should happen in the change control system for
your project. Theresa, a junior project manager, asks what the configuration management activities are
for scope changes. You tell her that all of the following are valid configuration management activities
except for which one?
A. Configuration Identification
B. Configuration Status Accounting
C. Configuration Item Costing
D. Configuration Verification and Auditing
Answer: C

NO.2 You work as a Security Manager for Tech Perfect Inc. You have set up a SIEM server for the following
purposes: Analyze the data from different log sources Correlate the events among the log entries Identify
and prioritize significant events Initiate responses to events if required One of your log monitoring staff
wants to know the features of SIEM product that will help them in these purposes. What features will you
recommend? Each correct answer represents a complete solution. Choose all that apply.
A. Transmission confidentiality protection
B. Graphical user interface
C. Security knowledge base
D. Asset information storage and correlation
E. Incident tracking and reporting
Answer: B,C,D,E

NO.3 Which of the following types of redundancy prevents attacks in which an attacker can get physical
control of a machine, insert unauthorized software, and alter data?
A. Data redundancy
B. Application redundancy
C. Process redundancy
D. Hardware redundancy
Answer: C

NO.4 Which of the following security design patterns provides an alternative by requiring that a user's
authentication credentials be verified by the database before providing access to that user's data?
A. Authenticated session
B. Account lockout
C. Secure assertion
D. Password propagation
Answer: D

