ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While validating the CSPRNG that seeds session-establishment keys in a new mobile payment application, you must produce solid evidence that the generator meets accepted entropy requirements. According to current NIST guidance, which test activity provides the most reliable proof of adequate entropy?
Collect 100 MB of output and run the NIST SP 800-22 statistical test suite looking for failed randomness tests.
Perform an entropy-source assessment and health-testing regimen in accordance with NIST SP 800-90B/800-90C, including review of seeding and reseeding logic.
Conduct mutation-based fuzzing of the CSPRNG API to detect crashes or hangs during number generation.
Benchmark the average CPU cycles required per random byte and compare the result to performance baselines.
NIST emphasizes that true assurance of a cryptographically secure pseudorandom number generator comes from validating its entropy source and overall design, following the requirements and health tests in NIST SP 800-90B and SP 800-90C. These publications define how to measure and bound the min-entropy available for seeding and how to verify continuous entropy during operation. Purely running the SP 800-22 statistical suite on output, benchmarking CPU performance, fuzzing the API, or inspecting comments about /dev/urandom may reveal implementation issues or obvious flaws, but they do not by themselves establish that the generator can produce the unpredictable bits required for cryptographic strength.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is entropy in the context of random number generation?
Open an interactive chat with Bash
What are NIST SP 800-90B and SP 800-90C?
Open an interactive chat with Bash
Why is the NIST SP 800-22 statistical test suite insufficient for validating entropy?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .