โ† All CISSP Flashcard Decks

Software Development Security Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Software Development Security flashcards as text
  1. Which threat modeling methodology uses attack trees and is primarily attacker-centric in its approach?

    Answer: PASTA

    PASTA (Process for Attack Simulation and Threat Analysis) is attacker-centric and uses attack trees to simulate adversarial objectives.

  2. A developer stores API keys directly in source code committed to a public repository. Which secure coding principle was violated?

    Answer: Hardcoded credential avoidance

    Hardcoded credentials in source code violate the principle of externalizing secrets into secure vaults or environment variables.

  3. What is the primary purpose of a Web Application Firewall (WAF) in a software security architecture?

    Answer: Filtering malicious HTTP traffic before it reaches the application

    A WAF inspects and filters HTTP/HTTPS requests to block common web attacks like SQLi and XSS before they reach the application.

  4. Which software development model integrates security activities such as abuse case development and attack surface analysis into each sprint?

    Answer: Agile SDL

    Agile SDL adapts security practices like abuse case modeling and attack surface analysis to fit iterative sprint cycles.

  5. An attacker manipulates a serialized object sent to a Java application causing remote code execution. What vulnerability class does this represent?

    Answer: Insecure deserialization

    Insecure deserialization occurs when an application deserializes attacker-controlled data, potentially enabling RCE or privilege escalation.

  6. Which metric in the CVSS v3 scoring system reflects whether a successful attack requires interaction from a user other than the attacker?

    Answer: User Interaction

    The User Interaction metric indicates whether exploitation requires a victim to perform an action, such as clicking a malicious link.

  7. What is the purpose of canary values placed on the stack by modern compilers?

    Answer: Detect stack buffer overflow before function returns

    Stack canaries are secret values placed before the return address; if overwritten by a buffer overflow they trigger a process termination.