KEO1 Secure Software Design Practice Questions
Prepare for KEO1 with more than an answer.
- Level
- Graduate/Master's
- Valid for
- Part of degree program - no separate certification expiration
Domains covered on the exam 4
- Security Methods within SDLC25%
- Software Requirements and Risk Assessment25%
- Software Security Test Planning and Threat Modeling25%
- Software Testing, Deployment, and Post-Release25%
- 1
A security analyst is performing a threat modeling exercise on a password reset function. The analyst identifies a risk where an attacker could initiate a password reset for a victim and then intercept the reset token sent to the victim's email. This would allow the attacker to take over the account. How would this threat be classified using STRIDE?
Show answer details
Correct answer: C
The core of this attack is Spoofing. The attacker is ultimately pretending to be the legitimate user to gain control of their account. By intercepting and using the reset token, the attacker effectively spoofs the user's identity to the system. While it leads to an Elevation of Privilege (gaining the user's access), the fundamental threat against the authentication mechanism itself is Spoofing.
- 2
What is the primary difference between fuzz testing and standard functional testing?
Show answer details
Correct answer: B
The core distinction is the nature of the input data. Functional testing is designed to verify that the software behaves correctly with expected inputs and use cases (positive testing). Fuzz testing, a form of negative testing, is designed to find security vulnerabilities and robustness issues by intentionally feeding the application malformed, invalid, and unexpected data to see if it crashes or behaves insecurely.
- 3
A security team is performing a gray box penetration test on a new API. Which of the following resources would they typically be provided with to conduct this type of test? (Select TWO)
Show answer details
Correct answer: B, D
In gray box testing, the tester has some, but not all, knowledge of the system. Providing user credentials is a common practice, allowing the tester to assess the application from an authenticated user's perspective without having full internal knowledge.
Providing API documentation gives the tester knowledge about the intended functionality, endpoints, and data structures. This partial knowledge is characteristic of a gray box test, allowing for more efficient and targeted testing than a black box approach, but without the full transparency of a white box test.
- 4
True or False: A key advantage of Dynamic Application Security Testing (DAST) is its ability to identify vulnerabilities in third-party libraries and components for which the source code is not available.
Show answer details
Correct answer: A
This statement is true. DAST operates by testing the running application from the outside, similar to a black box test. It sends various inputs and analyzes the outputs and behavior. Because it doesn't require source code, it can effectively probe the entire running application, including compiled third-party libraries, to find vulnerabilities like cross-site scripting or SQL injection that manifest at runtime.
- 5
A project manager is creating a security test plan. The plan includes a section for 'abuse cases'. What is the primary purpose of developing abuse cases?
Show answer details
Correct answer: C
Abuse cases are the inverse of use cases. While a use case describes how a system should work for a legitimate user, an abuse case describes how an attacker might misuse the system to compromise security. Their purpose is to help designers and testers think from an adversarial perspective to anticipate and mitigate potential attacks. They are a key input for security test planning.
- 6
A security architect is reviewing a new e-commerce feature that allows users to upload a profile picture. The architect is concerned about a specific risk where a user could upload a malicious file disguised as an image, which is then served to other users and potentially executed by their browsers. Which STRIDE category best classifies this specific threat?
Show answer details
Correct answer: C
The correct STRIDE category is Tampering. Tampering involves the unauthorized modification of data. In this scenario, the user is modifying the data (the profile picture file) to include malicious content, violating the integrity of the data store. While this could lead to Elevation of Privilege if the malicious file is executed, the initial act of altering the file itself falls under Tampering. Spoofing relates to identity, and Information Disclosure relates to confidentiality.
- 7
A QA team is preparing to test a new financial reporting application. The team has been given full access to the source code, detailed design documents, and architecture diagrams. They are tasked with creating test cases that validate specific logical paths and error-handling routines within the code. Which testing approach is being employed?
Show answer details
Correct answer: D
This scenario describes white box testing. White box testing is a method where the internal structure, design, and implementation of the item being tested are known to the tester. The key indicators here are the team's access to source code, design documents, and their task of validating specific logical paths within the code. Black box testing involves no knowledge of the internal workings, while gray box testing involves partial knowledge.
- 8
A Security Champion is training a new team of developers on secure coding practices. The champion emphasizes that when designing a system, it's crucial to ensure that a user cannot deny having performed an action. Which security principle is this related to, and which STRIDE category represents its failure?
Show answer details
Correct answer: C
The correct answer correctly maps the principle to its corresponding STRIDE threat. The security principle of Non-Repudiation ensures that a user cannot deny having performed a specific action. The failure to enforce this is categorized as a Repudiation threat in the STRIDE model. This is often achieved through robust logging, digital signatures, and audit trails.
- 9
A development team is building a healthcare application that must comply with HIPAA. The project manager is deciding between a Waterfall and an Agile methodology. Which of the following are compelling security-related reasons to choose a Waterfall model for this specific project? (Select TWO)
Show answer details
Correct answer: B, D
The Waterfall model's rigid, sequential nature makes it well-suited for projects where upfront requirements are critical and unlikely to change, such as those driven by strict regulatory compliance like HIPAA. Formal sign-offs at each stage provide a clear audit trail.
One of the key strengths of the Waterfall model is its emphasis on comprehensive documentation at every stage. This creates a robust paper trail that is highly beneficial during regulatory audits, making it easier to demonstrate that all HIPAA security requirements were considered and implemented.
