CSSLP 2024: Secure Software Testing
CSSLP 2024
| Expert
- 14 videos | 1h 48m 7s
- Includes Assessment
- Earns a Badge
Domain 6 of the CSSLP, Secure Software Testing, contains some of the most stunningly creative topics in the entire curriculum. For example, fuzz testing has been used to uncover not just vulnerabilities, but even obscure undocumented functionality. In this course, you'll learn how to contrast functional and non-functional security testing, white-box and black-box testing, while exploring testing environments in known and unknown configurations. Then, you'll explore security standards and guidelines, including the OWASP Testing Guide, SEI CERT best practices, OSSTMM framework, and NISTIR 8397. Next, you'll learn about vulnerability scanning and penetration testing, including attack surface validation, fuzz testing, simulation testing, and failure testing. You'll analyze the importance of entropy in cryptographic validation, study pseudorandom number generators, and study the role of undocumented functionality in secure development. Finally, you'll distinguish between defects, errors, and vulnerabilities, learn about CVSS scores, and review verification, validation, and acceptance testing techniques to ensure software quality and usability. This course prepares learners for the Certified Secure Software Lifecycle Professional (CSSLP) exam.
WHAT YOU WILL LEARN
-
Discover the key concepts covered in this courseDefine and contrast functional and non-functional security testing, as well as white-box and black-box testingDefine testing environment and contrast known and unknown environment testingDescribe the owasp testing guide, sei cert best practices, osstmm framework, nistir 8397 and other resources and standards for security testingDefine attack surface validation, vulnerability scanning and penetration testingDefine and analyze the uses of fuzzing (fuzz testing) and simulation testingDefine failure testing and analyze stress and break testing as well as run-time and compile-time fault injection
-
Outline the importance of high-quality and pseudorandom number generators in security and list sources and controls around entropyAnalyze security implications of documentation and undocumented functionalityDefine examples of build and break criteria and the impact of security tests on the product roadmapDistinguish defects, errors and vulnerabilities and analyze the role of cvss scores in addressing themContrast the generation of test data using automated tools with the secure reuse of production data in testingDefine and contrast verification and validation testing, and enumerate types of acceptance testingSummarize the key concepts covered in this course
IN THIS COURSE
-
2m 38sIn this video, you will discover the key concepts covered in this course. FREE ACCESS
-
10m 55sFind out how to define and contrast functional and non-functional security testing, as well as white-box and black-box testing. FREE ACCESS
-
5m 19sDuring this video, you will learn how to define testing environment and contrast known and unknown environment testing. FREE ACCESS
-
5m 48sLearn how to describe the OWASP Testing Guide, SEI CERT best practices, OSSTMM framework, NISTIR 8397 and other resources and standards for security testing. FREE ACCESS
-
11m 52sAfter completing this video, you will be able to define attack surface validation, vulnerability scanning and penetration testing. FREE ACCESS
-
8m 40sIn this video, find out how to define and analyze the uses of fuzzing (fuzz testing) and simulation testing. FREE ACCESS
-
5m 48sUpon completion of this video, you will be able to define failure testing and analyze stress and break testing as well as run-time and compile-time fault injection. FREE ACCESS
-
12m 8sLearn how to outline the importance of high-quality and pseudorandom number generators in security and list sources and controls around entropy. FREE ACCESS
-
9m 17sDuring this video, you will learn how to Analyze security implications of documentation and undocumented functionality. FREE ACCESS
-
8m 32sFind out how to define examples of build and break criteria and the impact of security tests on the product roadmap. FREE ACCESS
-
6m 42sIn this video, find out how to distinguish defects, errors and vulnerabilities and analyze the role of CVSS scores in addressing them. FREE ACCESS
-
12m 12sDiscover how to contrast the generation of test data using automated tools with the secure reuse of production data in testing. FREE ACCESS
-
5m 23sLearn how to define and contrast verification and validation testing, and enumerate types of acceptance testing. FREE ACCESS
-
2m 54sIn this video, we will summarize the key concepts covered in this course. FREE ACCESS
EARN A DIGITAL BADGE WHEN YOU COMPLETE THIS COURSE
Skillsoft is providing you the opportunity to earn a digital badge upon successful completion on some of our courses, which can be shared on any social network or business platform.
Digital badges are yours to keep, forever.