Software Development Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Software Development Security flashcards as text
Which technique involves inserting instrumentation into a running application to detect attacks in real time without modifying the source code?
Answer: Runtime Application Self-Protection (RASP)
RASP embeds security controls directly into an application's runtime environment, detecting and blocking attacks as the application executes.
A developer uses a third-party open-source component that contains a known critical vulnerability. Which process is MOST effective at systematically identifying this risk across an enterprise?
Answer: Software Composition Analysis (SCA)
SCA tools automatically inventory open-source dependencies and match them against vulnerability databases like NVD to flag known-vulnerable components.
Which XML-specific vulnerability allows an attacker to read arbitrary files on the server by referencing external entities in a crafted XML document?
Answer: XML External Entity (XXE) Injection
XXE injection exploits misconfigured XML parsers that process external entity references, enabling attackers to read local files or perform SSRF attacks.
In the context of secure software development, what is the definition of 'code signing'?
Answer: Applying a digital signature to software so recipients can verify its integrity and authenticity
Code signing uses a developer's private key to sign software, allowing users to verify via the corresponding public key that the code is untampered and from a trusted author.
Which access control model is MOST appropriate for applications that must enforce data confidentiality based on government-classified labels like Top Secret and Secret?
Answer: Mandatory Access Control (MAC)
MAC enforces access based on sensitivity labels assigned by the system, preventing users from sharing data above their clearance level regardless of their discretion.
A CI/CD pipeline automatically deploys code to production after tests pass. Which security control BEST reduces the risk of malicious code being deployed without human review?
Answer: Implementing mandatory code peer review and approval gates before merging
Mandatory peer review approval gates ensure at least one additional human verifies changes before they can be merged and deployed to production.
Which software security concept ensures that a module performs only the functions necessary for its purpose and does not have access to unneeded resources?
Answer: Principle of least privilege
The principle of least privilege limits software modules to only the permissions and resources they need to perform their defined function, reducing the blast radius of a compromise.