Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Secure Software DevelopmentEasy
Q1. What is a software vulnerability?
- A.A routine patch applied to update and improve existing system software
- B.A category of self-replicating malicious software designed for harm
- C.A weakness or flaw in software that can be exploited to compromise security✓ Correct
- D.A planned and well-documented software feature built for end users
Explanation
A software vulnerability is a weakness that could be exploited by an attacker.
Report an error in this question
Secure Software DevelopmentEasy
Q2. What is the SDLC?
- A.A high-level language used for development used in enterprise computing environments
- B.A database management system for storing data records
- C.A security tool for scanning and detecting vulnerabilities
- D.A structured process for planning, creating, testing, and deploying software✓ Correct
Explanation
The SDLC is a systematic process including planning, design, implementation, testing, deployment, and maintenance.
Report an error in this question
Secure Software DevelopmentEasy
Q3. Why is input validation important in secure coding?
- A.To ensure user input is safe and prevent malicious data from being processed✓ Correct
- B.To make the user interface look visually appealing
- C.To speed up the application processing and response time
- D.To reduce the overall file size of application resources
Explanation
Input validation prevents injection attacks and other vulnerabilities caused by malicious input.
Report an error in this question
Secure Software DevelopmentEasy
Q4. What is code review in secure development?
- A.Copying code from the internet without attribution or proper licensing
- B.Examining source code to identify security flaws, bugs, and code quality issues✓ Correct
- C.Permanently deleting old obsolete source code from repository branches
- D.Writing code faster without any verification of quality or correctness
Explanation
Code review systematically examines source code to find security vulnerabilities and coding errors.
Report an error in this question
Secure Software DevelopmentEasy
Q5. What is secure software development?
- A.Writing detailed technical documentation for all application code modules
- B.Only testing for bugs and defects at the very end of the development cycle
- C.Writing application code quickly without any formal quality review process
- D.Integrating security measures throughout the entire software development lifecycle✓ Correct
Explanation
Secure software development integrates security practices into every phase of the SDLC.
Report an error in this question
Secure Software DevelopmentEasy
Q6. What does 'security by design' mean?
- A.Adding security measures only after production deployment
- B.Building security into software from the earliest stages of development✓ Correct
- C.Installing antivirus software on the development machine
- D.Using only encryption as the single security measure
Explanation
Security by design means incorporating security considerations from the initial design phase.
Report an error in this question
Secure Software DevelopmentEasy
Q7. Why should default passwords be changed?
- A.To comply with organizational branding requirements
- B.To improve overall system performance and speed
- C.To make the login process more difficult for users
- D.Because default passwords are publicly known and easily exploited✓ Correct
Explanation
Default passwords are well-known and documented, making systems that use them easy targets.
Report an error in this question
Secure Software DevelopmentEasy
Q8. What is the purpose of using HTTPS in web applications?
- A.To block unwanted advertisements from displaying
- B.To encrypt data transmitted between client and server✓ Correct
- C.To compress web pages for reduced bandwidth usage
- D.To optimize the website for faster loading performance
Explanation
HTTPS encrypts browser-server communication, protecting sensitive data from interception.
Report an error in this question
Secure Software DevelopmentEasy
Q9. What is the purpose of error handling in secure coding?
- A.To deliberately cause the application to crash on errors
- B.To log all error details publicly for transparency
- C.To ignore all errors and continue processing without alerts
- D.To gracefully manage errors without exposing sensitive information✓ Correct
Explanation
Proper error handling ensures applications fail securely without disclosing sensitive information.
Report an error in this question
Secure Software DevelopmentEasy
Q10. What is a security bug?
- A.A physical hardware failure requiring component replacement
- B.A network connectivity issue affecting system availability
- C.A software defect that could be exploited to compromise system security✓ Correct
- D.A planned feature request from the product stakeholders
Explanation
A security bug is a coding error that creates a vulnerability.
Report an error in this question
Secure Software DevelopmentMedium
Q11. What is threat modeling in software development?
- A.Testing application performance under heavy load conditions
- B.Creating threat actors for penetration testing exercises
- C.Running antivirus scans on development machine environments
- D.A structured approach to identifying and addressing security threats during design✓ Correct
Explanation
Threat modeling systematically identifies potential threats and vulnerabilities during the design phase.
Report an error in this question
Secure Software DevelopmentMedium
Q12. What is the OWASP Secure Coding Practices guide?
- A.A high-level language used for development within modern computing environments
- B.A database design guide for managing enterprise data resources
- C.A comprehensive checklist of secure coding practices organized by vulnerability category✓ Correct
- D.A software application used for enterprise computing operations
Explanation
The OWASP Secure Coding Practices is a technology-agnostic set of secure coding guidelines.
Report an error in this question
Secure Software DevelopmentMedium
Q13. What is the principle of fail-safe defaults?
- A.Logging all defaults regardless of the specific situation or context
- B.Ignoring security failures within enterprise security environments
- C.Always granting access by default in security contexts
- D.Denying access by default and requiring explicit permission grants✓ Correct
Explanation
Fail-safe defaults deny access by default, requiring explicit authorization grants.
Report an error in this question
Secure Software DevelopmentMedium
Q14. What is dynamic application security testing (DAST)?
- A.Testing database query performance under heavy loads
- B.Testing a running application by simulating attacks to find vulnerabilities✓ Correct
- C.Testing source code without running it across computing environments
- D.Testing code compilation for syntax errors and warnings
Explanation
DAST tests a running application from the outside by simulating attacks.
Report an error in this question
Secure Software DevelopmentMedium
Q15. What is static application security testing (SAST)?
- A.Testing network performance under heavy traffic loads
- B.Testing user interfaces for usability and accessibility
- C.Analyzing source code without executing it to find security vulnerabilities✓ Correct
- D.Testing the application while it is actively running
Explanation
SAST analyzes source code without execution to identify security vulnerabilities.
Report an error in this question
Secure Software DevelopmentMedium
Q16. What is dependency management in secure development?
- A.Managing and coordinating team members across projects
- B.Tracking, updating, and securing third-party libraries and components✓ Correct
- C.Managing and configuring enterprise server infrastructure
- D.Managing database servers and optimizing query performance
Explanation
Dependency management involves tracking third-party libraries and checking them for known vulnerabilities.
Report an error in this question
Secure Software DevelopmentMedium
Q17. What is 'shift left' in security?
- A.Integrating security practices earlier in the development lifecycle✓ Correct
- B.Moving project deadlines earlier in the release timeline
- C.Moving physical servers to the left of the data center
- D.Changing code alignment and formatting in source files
Explanation
Shift left means incorporating security testing earlier in the SDLC rather than waiting until the end.
Report an error in this question
Secure Software DevelopmentMedium
Q18. What is the purpose of security testing in the SDLC?
- A.To deliberately delay the project delivery timeline
- B.To create comprehensive technical documentation materials
- C.To identify and fix security vulnerabilities before deployment to production✓ Correct
- D.To test and validate hardware components for compatibility
Explanation
Security testing identifies vulnerabilities before deployment, reducing risk and cost.
Report an error in this question
Secure Software DevelopmentHard
Q19. What is the concept of 'secure defaults'?
- A.Having no security settings or controls enabled at all regardless of the deployment context or scenario
- B.Using default vendor passwords for all system accounts across computing environments
- C.Shipping applications with the most secure configuration, requiring users to explicitly reduce security✓ Correct
- D.Applications require no configuration at all to operate regardless of the deployment context or scenario
Explanation
Secure defaults means applications ship with security enabled by default.
Report an error in this question
Secure Software DevelopmentMedium
Q20. What is the purpose of output encoding?
- A.Making output look visually pretty and well-formatted
- B.Compressing output data for reduced bandwidth consumption
- C.Encrypting output using symmetric cipher key algorithms
- D.Converting output to a safe format to prevent injection attacks like XSS✓ Correct
Explanation
Output encoding converts special characters to safe equivalents, preventing injection attacks.
Report an error in this question
Secure Software DevelopmentHard
Q21. What is Interactive Application Security Testing (IAST)?
- A.Manual code review conducted by human security reviewers
- B.A software application used for enterprise computing operations
- C.A hybrid combining SAST and DAST using instrumentation agents within the running application✓ Correct
- D.A type of unit test for verifying individual code functions used in enterprise computing environments
Explanation
IAST combines SAST and DAST elements by placing agents within the running application.
Report an error in this question
Secure Software DevelopmentHard
Q22. What is a Software Bill of Materials (SBOM)?
- A.A project plan for scheduling development milestones used in enterprise computing environments
- B.A software application used for enterprise computing operations
- C.A software license for managing application access rights
- D.A comprehensive inventory of all components, libraries, and dependencies in software✓ Correct
Explanation
An SBOM lists all components in software, enabling quick identification of affected systems when vulnerabilities are found.
Report an error in this question
Secure Software DevelopmentMedium
Q23. What is secure session management?
- A.Properly creating, maintaining, and destroying sessions to prevent hijacking and fixation✓ Correct
- B.Sharing sessions between multiple users simultaneously
- C.Deleting all cookies immediately after each page request
- D.Never creating sessions for any user interactions at all regardless of the deployment context or scenario
Explanation
Secure session management includes unpredictable session IDs, proper expiration, and secure cookie flags.
Report an error in this question
Secure Software DevelopmentHard
Q24. What is the Microsoft Security Development Lifecycle (SDL)?
- A.A Microsoft commercial product for endpoint security used in enterprise computing environments
- B.A testing framework for automated unit testing of code used in enterprise computing environments
- C.A high-level language used for development within modern computing environments
- D.A process integrating security into every SDLC phase including training, design, and verification✓ Correct
Explanation
Microsoft SDL integrates security into every SDLC phase including threat modeling, static analysis, and incident response.
Report an error in this question
Secure Software DevelopmentHard
Q25. What is the purpose of fuzz testing (fuzzing)?
- A.Load testing application performance under heavy traffic
- B.Providing random, unexpected, or malformed data as input to discover vulnerabilities✓ Correct
- C.Testing user experience through usability research sessions
- D.Testing application inputs with soft expected normal values
Explanation
Fuzzing sends random or malformed inputs to discover crashes, memory leaks, and buffer overflows.
Report an error in this question
Secure Software DevelopmentHard
Q26. What is taint analysis in secure development?
- A.Tracking untrusted data through an application to identify where it reaches sensitive operations unsanitized✓ Correct
- B.A color analysis tool for evaluating interface themes used in enterprise computing environments
- C.Source code formatting and style standardization practices across computing environments
- D.A code obfuscation method for protecting intellectual property used in enterprise computing environments
Explanation
Taint analysis tracks untrusted input data to identify where it reaches security-sensitive operations without sanitization.
Report an error in this question
Secure Software DevelopmentHard
Q27. What is Runtime Application Self-Protection (RASP)?
- A.A programming pattern used in enterprise computing environments
- B.Security technology built into an application that detects and prevents attacks in real-time✓ Correct
- C.A self-replicating strain of malicious software targeting systems
- D.A software application used for enterprise computing operations
Explanation
RASP integrates security into the running application, detecting and blocking attacks in real-time.
Report an error in this question
Secure Software DevelopmentHard
Q28. What is a security champion program in DevSecOps?
- A.Embedding security-trained developers within teams to advocate for security practices✓ Correct
- B.A competitive security skills competition between teams used in enterprise computing environments
- C.A hiring initiative for recruiting security professionals
- D.A certification program for professional security credentials
Explanation
Security champions are developers trained in security who promote secure coding practices within their teams.
Report an error in this question
Secure Software DevelopmentHard
Q29. What is DevSecOps?
- A.Integrating security into DevOps pipelines through automation, making security a shared responsibility✓ Correct
- B.A software application used for enterprise computing operations
- C.A next-generation firewall security appliance deployed across enterprise environments
- D.A high-level language used for development within modern computing environments
Explanation
DevSecOps integrates security into the DevOps pipeline, automating security testing throughout the lifecycle.
Report an error in this question
Secure Software DevelopmentHard
Q30. What is the purpose of a bug bounty program?
- A.Paying developers to write application source code faster and more efficiently
- B.Incentivizing external researchers to find and responsibly report vulnerabilities for rewards✓ Correct
- C.An automated software testing service for quality assurance and code validation
- D.A code quality improvement program focused on long-term maintainability goals
Explanation
Bug bounty programs invite external researchers to discover and report vulnerabilities.
Report an error in this question