Software Development Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Software Development Security flashcards as text
Which Agile security practice involves writing test cases for known attack scenarios before writing the feature code itself?
Answer: Abuse case development
Abuse cases (or misuse cases) define how an attacker could misuse a feature, guiding developers to build defenses proactively.
A legacy application uses MD5 to hash passwords. What is the PRIMARY cryptographic concern?
Answer: MD5 is cryptographically broken and collision-prone
MD5 is cryptographically broken, susceptible to collision attacks and extremely fast brute-force cracking, making it unsuitable for password hashing.
Which memory protection technique randomizes the location of key memory areas (stack, heap, executables) at runtime to impede exploitation?
Answer: Address Space Layout Randomization (ASLR)
ASLR randomizes the base addresses of memory regions at each execution, making it harder for attackers to predict jump targets for exploits.
In a secure SDLC, at which phase should security requirements be FIRST formally defined?
Answer: Requirements
Security requirements must be defined during the Requirements phase so that security controls are architected and built in from the beginning rather than bolted on later.
Which secure design principle dictates that a system should deny access by default and only grant access when explicitly permitted?
Answer: Fail-safe defaults
Fail-safe defaults means access is denied unless explicitly granted, ensuring that errors or omissions result in a secure (locked) state rather than open access.
What is a primary security risk of using eval() functions in interpreted languages such as JavaScript or Python?
Answer: Arbitrary code execution if user input is evaluated
eval() executes its string argument as code; if user-controlled input reaches eval(), an attacker can inject and execute arbitrary code.
Which type of testing sends random, malformed, or unexpected inputs to an application interface to discover crashes and vulnerabilities?
Answer: Fuzz testing
Fuzz testing (fuzzing) automatically generates large volumes of invalid or random inputs to trigger unexpected behavior, crashes, or security flaws.