Software Security & Risk Management Flashcards
7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Software Security & Risk Management flashcards as text
Which risk treatment option involves accepting the potential consequences of a risk without taking additional action?
Answer: Risk acceptance
Risk acceptance means acknowledging a risk and choosing not to act further, often when the cost of mitigation exceeds the potential impact.
A software manager wants to ensure that no single employee can both approve and execute a financial transaction in a system. Which security principle does this enforce?
Answer: Separation of duties
Separation of duties divides critical tasks among multiple people to prevent fraud or error by any single individual.
During a penetration test, testers are given full knowledge of the system architecture and source code. This approach is called:
Answer: White-box testing
White-box (or clear-box) penetration testing gives testers complete internal knowledge of the system being tested.
What is the PRIMARY purpose of a Security Information and Event Management (SIEM) system?
Answer: Centrally collecting and correlating security logs for threat detection
A SIEM aggregates and correlates log data from multiple sources to detect security incidents in real time.
Which software vulnerability allows an attacker to read memory outside the bounds of an allocated buffer?
Answer: Buffer overflow
A buffer overflow occurs when a program writes or reads beyond the memory allocated for a buffer, potentially exposing sensitive data or enabling code execution.
A risk register entry shows a vulnerability with LOW likelihood but HIGH impact. How should a software manager prioritize it?
Answer: Monitor it and plan contingency measures
Low-likelihood, high-impact risks warrant monitoring and contingency planning rather than immediate full-scale mitigation.
Which type of malware disguises itself as legitimate software while secretly enabling unauthorized access to a system?
Answer: Trojan horse
A Trojan horse appears to be benign or useful software but contains hidden malicious functionality that enables attacker access.