ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A software assurance team is choosing OSSTMM as its baseline testing standard and wants to report the security posture of each tested environment with a single quantitative value that can be trended over time. According to the OSSTMM, which output should the team use to satisfy this requirement?
A DREAD risk rating derived from each identified threat
The Security Test Audit Report (STAR) score produced at the end of an OSSTMM assessment
A STRIDE categorization table generated during threat modeling
The Common Vulnerability Scoring System (CVSS) base score calculated for discovered findings
The OSSTMM aggregates the detailed test findings for each operational channel into a Security Test Audit Report (STAR) score. The STAR score is a single numeric value that reflects the level of operational security measured during the assessment and can be compared from one test cycle to the next. CVSS, DREAD, and STRIDE are risk-rating or threat-modeling approaches that are not defined by the OSSTMM standard and do not provide a stand-alone quantitative index produced directly by an OSSTMM assessment.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is OSSTMM?
Open an interactive chat with Bash
What is the STAR score in OSSTMM?
Open an interactive chat with Bash
How does OSSTMM differ from CVSS, DREAD, and STRIDE?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .