โ† All CISSP Flashcard Decks

Software Development Security Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Software Development Security flashcards as text
  1. Which type of code review technique has reviewers examine source code without executing it, looking for logic flaws and vulnerabilities?

    Answer: Static analysis

    Static analysis (or static code review) inspects source or binary code without running it, identifying vulnerabilities through pattern and logic analysis.

  2. A CISSP candidate evaluates a third-party library with an open-source license. What is the MOST critical security concern for software supply chain integrity?

    Answer: Verifying the library's cryptographic hash against the official repository

    Verifying cryptographic hashes ensures the downloaded library has not been tampered with during distribution (supply chain attack prevention).

  3. Which software assurance concept involves identifying the minimum set of interfaces and entry points exposed by an application to reduce its attack exposure?

    Answer: Attack surface reduction

    Attack surface reduction minimizes the number of exposed code paths, APIs, and interfaces that could be exploited by attackers.

  4. In OAuth 2.0, which grant type is considered MOST risky because it exposes access tokens in the browser URL fragment?

    Answer: Implicit

    The implicit grant type returns tokens directly in the URL fragment, making them visible in browser history and logs, and is now deprecated in OAuth 2.1.

  5. What is the role of a Security Champions program within a software development organization?

    Answer: Embedding security-aware developers within each product team to promote secure coding

    Security Champions are developers embedded in product teams who promote security awareness and act as liaisons to the central security team.

  6. Which database security control prevents an attacker who obtains a dump of hashed passwords from immediately cracking common passwords using precomputed rainbow tables?

    Answer: Password salting

    Salting adds a unique random value to each password before hashing, making precomputed rainbow table attacks ineffective.

  7. An application allows users to upload files and immediately executes them on the server. Which vulnerability does this PRIMARILY represent?

    Answer: Remote code execution via unrestricted file upload

    Unrestricted file upload without type validation and execution prevention allows attackers to upload and execute malicious scripts or binaries.