Software Security & Risk Management Flashcards
7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Software Security & Risk Management flashcards as text
During an incident response, a team isolates a compromised server from the network immediately after discovery. This action corresponds to which phase of the NIST incident response lifecycle?
Answer: Containment, eradication, and recovery
Containment is the immediate step to prevent further damage after an incident is confirmed, followed by eradication and recovery.
What is the key difference between a vulnerability assessment and a penetration test?
Answer: Vulnerability assessments identify weaknesses; penetration tests actively exploit them
A vulnerability assessment finds and reports weaknesses, while a penetration test goes further by attempting to exploit those weaknesses to demonstrate real impact.
A software manager implements role-based access control (RBAC). What is the PRIMARY security benefit?
Answer: Ensures users only access resources required for their job function
RBAC restricts system access based on defined roles, enforcing least privilege so users can only access what their role requires.
Which of the following BEST describes a supply chain attack in software security?
Answer: Compromising a trusted third-party component or tool to target downstream users
A supply chain attack targets trusted software dependencies, build pipelines, or vendors to inject malicious code that reaches end users through trusted channels.
What risk management concept describes the maximum tolerable downtime for a critical software system before business impact becomes unacceptable?
Answer: Recovery Time Objective (RTO)
RTO defines how quickly a system must be restored after a failure to avoid unacceptable business consequences.
An attacker sends thousands of requests to a web application to exhaust its resources and deny access to legitimate users. This is an example of:
Answer: Denial of Service (DoS) attack
A DoS attack overwhelms a system's resources — bandwidth, CPU, or memory — to make it unavailable to legitimate users.
Which document formally authorizes a software project's information security risk management plan and assigns accountability?
Answer: Risk acceptance memo signed by senior management
A signed risk acceptance memo from senior management formally documents that leadership acknowledges and accepts the identified residual risks.