Secure Software Design Free Sample Questions

19 free sample questions289 in the full practice test

Try simulator

KEO1 Sample Questions

  1. Question 1

    A security architect is reviewing a new e-commerce feature that allows users to upload a profile picture. The architect is concerned about a specific risk where a user could upload a malicious file disguised as an image, which is then served to other users and potentially executed by their browsers. Which STRIDE category best classifies this specific threat?

    Answer and explanation

    Correct answer: C

    The correct STRIDE category is Tampering. Tampering involves the unauthorized modification of data. In this scenario, the user is modifying the data (the profile picture file) to include malicious content, violating the integrity of the data store. While this could lead to Elevation of Privilege if the malicious file is executed, the initial act of altering the file itself falls under Tampering. Spoofing relates to identity, and Information Disclosure relates to confidentiality.

  2. Question 2

    A QA team is preparing to test a new financial reporting application. The team has been given full access to the source code, detailed design documents, and architecture diagrams. They are tasked with creating test cases that validate specific logical paths and error-handling routines within the code. Which testing approach is being employed?

    Answer and explanation

    Correct answer: D

    This scenario describes white box testing. White box testing is a method where the internal structure, design, and implementation of the item being tested are known to the tester. The key indicators here are the team's access to source code, design documents, and their task of validating specific logical paths within the code. Black box testing involves no knowledge of the internal workings, while gray box testing involves partial knowledge.

  3. Question 3

    A Security Champion is training a new team of developers on secure coding practices. The champion emphasizes that when designing a system, it's crucial to ensure that a user cannot deny having performed an action. Which security principle is this related to, and which STRIDE category represents its failure?

    Answer and explanation

    Correct answer: C

    The correct answer correctly maps the principle to its corresponding STRIDE threat. The security principle of Non-Repudiation ensures that a user cannot deny having performed a specific action. The failure to enforce this is categorized as a Repudiation threat in the STRIDE model. This is often achieved through robust logging, digital signatures, and audit trails.

  4. Question 4

    Multiple answers

    A development team is building a healthcare application that must comply with HIPAA. The project manager is deciding between a Waterfall and an Agile methodology. Which of the following are compelling security-related reasons to choose a Waterfall model for this specific project? (Select TWO)

    Answer and explanation

    Correct answers: B, D

    The Waterfall model's rigid, sequential nature makes it well-suited for projects where upfront requirements are critical and unlikely to change, such as those driven by strict regulatory compliance like HIPAA. Formal sign-offs at each stage provide a clear audit trail.

    One of the key strengths of the Waterfall model is its emphasis on comprehensive documentation at every stage. This creates a robust paper trail that is highly beneficial during regulatory audits, making it easier to demonstrate that all HIPAA security requirements were considered and implemented.

  5. Question 5

    True or False: In the context of the Building Security In Maturity Model (BSIMM), an organization's maturity score is calculated by comparing its observed security activities against a predefined, static set of ideal best practices.

    Answer and explanation

    Correct answer: B

    This statement is false. A key characteristic of the BSIMM is that it is a descriptive model, not a prescriptive one. It doesn't define a static set of best practices. Instead, it is a study of real-world software security initiatives. An organization's maturity is benchmarked against the observed activities of other participating organizations, providing a relative measure of maturity based on current industry practices.

  6. Question 6

    A new social media platform is undergoing a security review before launch. The security team decides to use the DREAD model to prioritize identified threats. A potential vulnerability is rated as follows:

    • Damage: 9 (Full system compromise)
    • Reproducibility: 10 (Always reproducible)
    • Exploitability: 8 (Requires an authenticated, but standard, user)
    • Affected Users: 10 (All users)
    • Discoverability: 5 (Difficult to find)

    What is the overall DREAD risk score for this vulnerability?

    Answer and explanation

    Correct answer: A

    The DREAD risk score is calculated by taking the average of the five categories. The calculation is (Damage + Reproducibility + Exploitability + Affected Users + Discoverability) / 5. In this case, (9 + 10 + 8 + 10 + 5) / 5 = 42 / 5 = 8.4. This score would typically be classified as a High risk.

  7. Question 7

    During a dynamic analysis of a web application, a security tester observes that appending ?debug=true to a URL exposes detailed stack traces and database error messages. While this doesn't grant unauthorized access directly, it reveals the internal structure of the application and specific technologies used. Which STRIDE category is most appropriate for this finding?

    Answer and explanation

    Correct answer: D

    This finding is a classic example of an Information Disclosure threat. The application is revealing sensitive internal details (stack traces, database errors, technologies) to unauthorized parties. This information violates confidentiality and can be used by an attacker to craft more targeted attacks, even though it doesn't directly grant access. It's a breach of confidentiality, which is the core of this STRIDE category.

  8. Question 8

    Case Study

    A mid-sized insurance company, InsureRight, is developing a new customer claims portal. The portal will handle sensitive customer data, including personal identifiable information (PII) and protected health information (PHI). The development team follows an Agile methodology with two-week sprints. The company has a mature security program but is struggling to integrate it effectively into the fast-paced Agile workflow. The Chief Information Security Officer (CISO) is concerned that security is being treated as an afterthought, with security testing only happening in a final 'hardening' sprint before release.

    Current Situation:
    The development team consists of 15 developers, 4 QA testers, and 2 product owners. They do not have a dedicated application security engineer. Security knowledge is inconsistent across the team. The current process involves developers completing user stories, which are then passed to QA. The security team performs a penetration test two weeks before the scheduled release, often finding critical issues that cause significant delays.

    Requirements:
    The CISO wants to implement a 'shift-left' security strategy without disrupting the Agile process. The solution must be scalable and foster a culture of security ownership within the development team. The goal is to identify and remediate vulnerabilities as early as possible in the development lifecycle.

    Which of the following strategies would be the MOST effective first step for InsureRight to integrate security into their Agile process?

    Answer and explanation

    Correct answer: C

    This is the most effective first step because it addresses the core cultural and resource issues. A Security Champions program scales the security team's efforts by embedding security knowledge directly into the development team. This approach fosters ownership, provides immediate security guidance during development, and is a foundational step for introducing other 'shift-left' activities like threat modeling and secure code reviews in a way that aligns with Agile principles. It directly addresses the lack of a dedicated security engineer and inconsistent knowledge.

  9. Question 9

    A project requires a detailed analysis of potential privacy risks associated with handling customer PII before development begins. This analysis will document how data is collected, used, and stored, and will assess compliance with regulations like GDPR. What is this formal process called?

    Answer and explanation

    Correct answer: C

    A Privacy Impact Assessment (PIA), also known as a Data Protection Impact Assessment (DPIA) under GDPR, is a formal process used to identify and mitigate privacy risks. It specifically focuses on the handling of personal information and ensuring compliance with privacy laws, which matches the description perfectly. A threat model or general security risk assessment would focus on security threats rather than specifically on privacy compliance.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 289 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon