12 questions

Software Development Security

A software vendor sets up a public web page and security mailbox so researchers and customers can report vulnerabilities in its products. Which NIST SSDF practice group does this support?

  • a.Produce Well-Secured Software (PW)
  • b.Respond to Vulnerabilities (RV)✓
  • c.Protect the Software (PS)
  • d.Prepare the Organization (PO)

NIST SP 800-218 task RV.1.1 is to gather information from software acquirers, users and public sources on potential vulnerabilities, which a reporting channel supports; the RV group covers identifying, remediating and analyzing vulnerabilities after release. PO covers people, processes and technology readiness, PS covers protecting code and releases from tampering, and PW covers secure design, coding and testing.

Software Development Security

After fixing a SQL injection flaw in one module, the development lead wants to prevent the same mistake elsewhere. What does the NIST SSDF recommend?

  • a.Wait for customers to report other instances
  • b.Find the root cause and look for similar flaws✓
  • c.Remove the database from the application design
  • d.Close the ticket once the one module is patched

NIST SP 800-218 practice RV.3 calls for analyzing vulnerabilities to identify their root causes, including reviewing software for other instances of the same problem and improving processes so it does not recur. Closing after one fix, redesigning away the database, or waiting for customer reports leaves sibling flaws in place.

Software Development Security

A team runs one tool that analyzes source code without executing it and another that sends crafted requests to the running application. Which pairing is correct?

  • a.Dynamic testing (DAST), then static analysis (SAST)
  • b.Composition analysis (SCA), then interactive testing (IAST)
  • c.Static analysis (SAST), then dynamic testing (DAST)✓
  • d.Interactive testing (IAST), then composition analysis (SCA)

Analyzing code without running it is static application security testing, matching SSDF practice PW.7 (review and/or analyze human-readable code); probing the running application is dynamic testing, matching PW.8 (test executable code). SCA inventories third-party components, and IAST instruments the running application from inside, so neither describes the first tool.

Software Development Security

An application uses dozens of open-source libraries, and nobody tracks their versions. Which control does current OWASP Top 10 guidance recommend to automate tracking of vulnerable components?

  • a.Running the application only on internal networks
  • b.Obfuscating the application's own source code
  • c.Rewriting all libraries in-house from scratch
  • d.Software composition analysis (SCA)✓

OWASP Top 10:2025 A03 (Software Supply Chain Failures, which absorbed A06:2021 Vulnerable and Outdated Components) recommends continuously inventorying client- and server-side component versions and their dependencies, monitoring CVE/NVD/OSV, and using software composition analysis or SBOM tools to automate this; SSDF PW.4 similarly favors acquiring and maintaining well-secured components. Obfuscation hides nothing from attackers probing the vulnerable library, rewriting everything is impractical, and network location does not patch components.

Software Development Security

A login form builds its SQL statement by concatenating the username that users type. What is the preferred fix according to the OWASP Top 10 injection guidance?

  • a.Use a safe API or parameterized queries✓
  • b.Limit the username field to 20 characters
  • c.Encrypt the database files at rest
  • d.Hide database error messages from users

The OWASP Top 10 Injection category (A05:2025, A03:2021) states the preferred option is a safe API that avoids the interpreter or provides a parameterized interface, keeping data separate from commands; positive server-side input validation and escaping are secondary measures. Hiding errors only makes injection harder to see, a length limit still allows short payloads, and encryption at rest does nothing against queries run through the application.

Software Development Security

A customer changes the invoice number in the URL from 10452 to 10453 and sees another customer's invoice. Which OWASP Top 10 category is this, and what fixes it?

  • a.Cryptographic failures; encrypt the invoice numbers
  • b.Security misconfiguration; disable directory listing
  • c.Injection; escape special characters in the URL
  • d.Broken access control; check ownership server-side✓

OWASP Top 10 A01 Broken Access Control (2021 and 2025 editions) lists permitting viewing someone else's account by providing its unique identifier (insecure direct object reference) as broken access control, and its prevention guidance says access controls should enforce record ownership. Nothing is being injected into an interpreter, encrypting IDs only obscures them without checking ownership, and directory listing is unrelated.

Software Development Security

A development team validates all form input with JavaScript in the browser and performs no checks on the server. Why is this insufficient?

  • a.Client-side checks slow down every page load
  • b.JavaScript cannot check the length of input
  • c.Requests can be sent directly, bypassing the browser✓
  • d.Browsers disable JavaScript on login pages

Anything running in the client is under the attacker's control, so requests can be crafted without passing through the page's scripts; OWASP's Injection guidance (A05:2025) recommends positive server-side input validation, and Broken Access Control (A01:2025) notes controls are only effective in trusted server-side code. JavaScript can check length, browsers do not disable it on login pages, and performance is not the security issue.

Software Development Security

An organization wants to ensure that source code cannot be altered by unauthorized people. Which NIST SSDF practice addresses this?

  • a.Reuse existing, well-secured software (PW.4)
  • b.Test executable code for vulnerabilities (PW.8)
  • c.Respond to vulnerabilities on an ongoing basis (RV.1)
  • d.Protect code from unauthorized access (PS.1)✓

NIST SP 800-218 practice PS.1 requires storing all forms of code, including source, executable and configuration-as-code, with access restricted and changes tracked to prevent unauthorized access and tampering. RV.1 concerns finding vulnerabilities after release, PW.4 concerns component reuse, and PW.8 concerns testing, none of which restricts who can alter the code.

Software Development Security

A product team signs its release packages and publishes hashes on a separate, well-secured site so customers can check what they download. Which SSDF practice is this?

  • a.Verify software release integrity (PS.2)✓
  • b.Define security requirements for development (PO.1)
  • c.Configure software to have secure settings by default (PW.9)
  • d.Archive and protect each software release (PS.3)

NIST SP 800-218 PS.2 is to help acquirers ensure the software they get is legitimate and untampered, with task PS.2.1 making integrity verification information such as posted hashes and signatures available. PO.1 defines requirements, PS.3 archives release data for later analysis, and PW.9 concerns secure default settings.

Software Development Security

In the SEI Capability Maturity Model, an organization's software process is documented, standardized and integrated into a standard process used across all projects. Which maturity level is this?

  • a.Level 3 — Defined✓
  • b.Level 2 — Repeatable
  • c.Level 1 — Initial
  • d.Level 5 — Optimizing

The SEI Capability Maturity Model for Software defines five levels: Initial, Repeatable, Defined, Managed and Optimizing; at the Defined level the process is documented and standardized into an organization-wide standard process. Initial is ad hoc, Repeatable has project-level management practices that let earlier successes be repeated, and Optimizing focuses on continuous process improvement.

Want these explained in order? CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Software Development Security

A DevSecOps team wants security flaws found as early and cheaply as possible without slowing releases. Which approach fits NIST SSDF guidance?

  • a.Automated checks in the CI/CD pipeline✓
  • b.One manual penetration test a year
  • c.Customer bug reports after release
  • d.Review only at major version releases

NIST SP 800-218 practice PO.3 calls for implementing supporting toolchains and automation, and PW.7 and PW.8 call for code analysis and testing throughout development, which a CI/CD pipeline makes routine. An annual test, waiting for customer reports, or reviewing only at major releases finds flaws late, when they cost more to fix.

Software Development Security

A company is about to buy a commercial off-the-shelf application for processing customer data. Which step best assesses the security impact of this acquired software?

  • a.Trust it because it is widely sold
  • b.Ask for secure-development evidence and an SBOM✓
  • c.Test only the user interface and usability
  • d.Review its security after deployment

The ISC2 outline covers assessing the security impact of COTS software, and NIST SP 800-218 PO.1.3 has organizations communicate security requirements to third-party suppliers, while an SBOM shows the components the product contains. Market popularity is not assurance, usability testing does not examine security, and reviewing after deployment exposes customer data first.

Report