โ† All CSM Flashcard Decks

Software Security & Risk Management Flashcards

7 cards from real CSM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Software Security & Risk Management flashcards as text
  1. Which cryptographic concept ensures that a sender cannot later deny having sent a message?

    Answer: Non-repudiation

    Non-repudiation uses digital signatures or audit logs to provide proof of origin, preventing a sender from denying their actions.

  2. A software team uses static application security testing (SAST) tools. At what stage of the SDLC is SAST MOST effectively applied?

    Answer: During the coding and build phase

    SAST analyzes source code or binaries without executing the program, making it most effective during development and build phases to catch issues early.

  3. What is 'threat modeling' in software security management?

    Answer: A structured process to identify, quantify, and address security threats during design

    Threat modeling proactively identifies potential threats and vulnerabilities during the design phase so mitigations can be built into the system from the start.

  4. A company requires all software changes to be reviewed and approved by a separate team before deployment. This is an example of which control type?

    Answer: Preventive control

    A preventive control stops an undesirable event from occurring; requiring change approval before deployment prevents unauthorized or flawed code from reaching production.

  5. Which vulnerability in web applications occurs when unsanitized user input is executed as script in another user's browser?

    Answer: Cross-Site Scripting (XSS)

    XSS injects malicious client-side scripts into web pages viewed by other users, enabling session hijacking, defacement, or malicious redirects.

  6. In risk management, what does a 'risk appetite' statement define?

    Answer: The level of risk an organization is willing to accept in pursuit of its objectives

    Risk appetite articulates how much risk an organization is willing to tolerate, guiding decisions about which risks to mitigate, accept, or avoid.

  7. Which protocol is used to securely transfer files by encrypting both authentication credentials and data in transit?

    Answer: SFTP

    SFTP (SSH File Transfer Protocol) encrypts both the authentication process and file data during transfer, unlike plain FTP which transmits credentials in cleartext.