← All CSM Flashcard Decks

Software Security & Risk Management Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Software Security & Risk Management flashcards as text
  1. In the context of software risk management, what does 'residual risk' refer to?

    Answer: Risk remaining after controls have been applied

    Residual risk is the level of risk that remains after mitigation controls have been implemented.

  2. Which authentication method requires users to provide something they know AND something they have?

    Answer: Multi-factor authentication

    Multi-factor authentication combines two or more distinct verification factors (knowledge, possession, or inherence) to validate identity.

  3. A software team discovers that a critical third-party library they use has an unpatched zero-day vulnerability. The BEST immediate action is:

    Answer: Disable or replace the affected component while evaluating alternatives

    When a critical zero-day is found in a dependency, disabling or replacing it immediately reduces exposure while a permanent fix is sought.

  4. What does the 'integrity' component of the CIA triad ensure in software security?

    Answer: Data remains accurate and unaltered by unauthorized parties

    Integrity ensures that data and systems are accurate and have not been improperly modified by unauthorized users or processes.

  5. Which secure coding practice directly reduces the risk of injection attacks such as SQL injection?

    Answer: Using parameterized queries or prepared statements

    Parameterized queries separate SQL code from user-supplied data, preventing attackers from injecting malicious SQL commands.

  6. A software manager is assessing vendor risk for a cloud provider. Which document BEST summarizes the provider's security controls and audit results?

    Answer: SOC 2 Type II report

    A SOC 2 Type II report provides an independent auditor's assessment of a service provider's security, availability, and confidentiality controls over time.

  7. Which risk analysis technique assigns numerical probabilities and financial values to produce a quantitative risk score?

    Answer: Annualized Loss Expectancy (ALE) calculation

    ALE = Single Loss Expectancy × Annual Rate of Occurrence, providing a dollar-value estimate of expected annual loss from a risk.