Question 161

The Data and Analysis Center for Software (DACS) specifies three general principles for software assurance which work as a framework in order to categorize various secure design principles. Which of the following principles and practices does the General Principle 1 include? Each correct answer represents a complete solution. Choose two.
  • Question 162

    According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnerability scenario using some functions. Which of the following are functions that are used by the dynamic analysis tools and are summarized in the NIST SAMATE? Each correct answer represents a complete solution. Choose all that apply.
  • Question 163

    Which of the following NIST documents provides a guideline for identifying an information system as a National Security System?
  • Question 164

    In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete solution.
    Choose all that apply.
  • Question 165

    In which of the following testing methods is the test engineer equipped with the knowledge of system and designs test cases or test data based on system knowledge?