KEO1 Sample Questions & Answers
Four areas split the weighting evenly: software security basics and testing methods within the SDLC, development approaches paired with assessing risk, modeling threats while planning tests, and testing, deployment and what happens after release.
Launch the full KEO1 simulator →Showing 9 of 19 free samples.
- Question 1Intermediate
Evaluates Effectiveness of Software Testing · Security Frameworks and Maturity Models
True or False: In the context of the Building Security In Maturity Model (BSIMM), an organization's maturity score is calculated by comparing its observed security activities against a predefined, static set of ideal best practices.
Show answer & explanation
Correct answer: B
This statement is false. A key characteristic of the BSIMM is that it is a descriptive model, not a prescriptive one. It doesn't define a static set of best practices. Instead, it is a study of real-world software security initiatives. An organization's maturity is benchmarked against the observed activities of other participating organizations, providing a relative measure of maturity based on current industry practices.
- Question 2Intermediate
Evaluates Software Security Test Plan · DREAD Risk Assessment
A new social media platform is undergoing a security review before launch. The security team decides to use the DREAD model to prioritize identified threats. A potential vulnerability is rated as follows:
- Damage: 9 (Full system compromise)
- Reproducibility: 10 (Always reproducible)
- Exploitability: 8 (Requires an authenticated, but standard, user)
- Affected Users: 10 (All users)
- Discoverability: 5 (Difficult to find)
What is the overall DREAD risk score for this vulnerability?
Show answer & explanation
Correct answer: A
The DREAD risk score is calculated by taking the average of the five categories. The calculation is (Damage + Reproducibility + Exploitability + Affected Users + Discoverability) / 5. In this case, (9 + 10 + 8 + 10 + 5) / 5 = 42 / 5 = 8.4. This score would typically be classified as a High risk.
- Question 3Intermediate
Evaluates Software Security Test Plan · STRIDE Threat Model
During a dynamic analysis of a web application, a security tester observes that appending
?debug=trueto a URL exposes detailed stack traces and database error messages. While this doesn't grant unauthorized access directly, it reveals the internal structure of the application and specific technologies used. Which STRIDE category is most appropriate for this finding?Show answer & explanation
Correct answer: D
This finding is a classic example of an Information Disclosure threat. The application is revealing sensitive internal details (stack traces, database errors, technologies) to unauthorized parties. This information violates confidentiality and can be used by an attacker to craft more targeted attacks, even though it doesn't directly grant access. It's a breach of confidentiality, which is the core of this STRIDE category.
- Question 4Advanced
Assesses Software Requirements and Risks · Agile Development Security
Case Study
A mid-sized insurance company, InsureRight, is developing a new customer claims portal. The portal will handle sensitive customer data, including personal identifiable information (PII) and protected health information (PHI). The development team follows an Agile methodology with two-week sprints. The company has a mature security program but is struggling to integrate it effectively into the fast-paced Agile workflow. The Chief Information Security Officer (CISO) is concerned that security is being treated as an afterthought, with security testing only happening in a final 'hardening' sprint before release.
Current Situation:
The development team consists of 15 developers, 4 QA testers, and 2 product owners. They do not have a dedicated application security engineer. Security knowledge is inconsistent across the team. The current process involves developers completing user stories, which are then passed to QA. The security team performs a penetration test two weeks before the scheduled release, often finding critical issues that cause significant delays.Requirements:
The CISO wants to implement a 'shift-left' security strategy without disrupting the Agile process. The solution must be scalable and foster a culture of security ownership within the development team. The goal is to identify and remediate vulnerabilities as early as possible in the development lifecycle.Which of the following strategies would be the MOST effective first step for InsureRight to integrate security into their Agile process?
Show answer & explanation
Correct answer: C
This is the most effective first step because it addresses the core cultural and resource issues. A Security Champions program scales the security team's efforts by embedding security knowledge directly into the development team. This approach fosters ownership, provides immediate security guidance during development, and is a foundational step for introducing other 'shift-left' activities like threat modeling and secure code reviews in a way that aligns with Agile principles. It directly addresses the lack of a dedicated security engineer and inconsistent knowledge.
- Question 5Beginner
Assesses Software Requirements and Risks · Privacy Impact Assessment (PIA)
A project requires a detailed analysis of potential privacy risks associated with handling customer PII before development begins. This analysis will document how data is collected, used, and stored, and will assess compliance with regulations like GDPR. What is this formal process called?
Show answer & explanation
Correct answer: C
A Privacy Impact Assessment (PIA), also known as a Data Protection Impact Assessment (DPIA) under GDPR, is a formal process used to identify and mitigate privacy risks. It specifically focuses on the handling of personal information and ensuring compliance with privacy laws, which matches the description perfectly. A threat model or general security risk assessment would focus on security threats rather than specifically on privacy compliance.
- Question 6IntermediateSelect 2
Examines Security Methods within SDLC · Static Analysis
Which of the following activities are characteristic of Static Application Security Testing (SAST)? (Select TWO)
Show answer & explanation
Correct answers: B, D
SAST involves analyzing the application's code without executing it. Scanning for insecure patterns, functions, or dependencies directly within the source code is a core feature of SAST tools.
This is a characteristic of static analysis. SAST tools often parse the source code or compiled bytecode to build abstract models like control-flow graphs or abstract syntax trees to analyze the application's structure and logic without running it.
- Question 7Intermediate
Evaluates Effectiveness of Software Testing · Security Frameworks and Maturity Models
A software team is trying to improve its security posture. Management wants to adopt a prescriptive framework that provides a clear roadmap for incrementally improving their security practices across different business functions. They want a model that defines specific activities and maturity levels. Which framework best suits this requirement?
Show answer & explanation
Correct answer: C
OWASP SAMM (OpenSAMM) is the best fit for this requirement. It is a prescriptive model designed to be a roadmap for building a software security program. It defines various security practices across business functions (like Governance, Design, Implementation) and provides three maturity levels for each, allowing organizations to incrementally improve and measure their progress. BSIMM, in contrast, is descriptive and used for benchmarking against what other companies are doing.
- Question 8Intermediate
Assesses Software Requirements and Risks · Functional vs Non-Functional Security Requirements
A developer is writing a non-functional requirement for a new API endpoint. The requirement states: "The API endpoint must validate that the user is authorized to access the requested resource and log all failed access attempts." How should this requirement be classified?
Show answer & explanation
Correct answer: A
Despite the developer's initial classification, this is a functional security requirement. Functional requirements define what a system is supposed to DO. In this case, the system must perform specific actions: validating authorization and logging failures. These are concrete functions the system must execute. Non-functional requirements describe how a system performs (e.g., performance, scalability, reliability), such as 'the authorization check must complete in under 50ms'.
- Question 9Advanced
Evaluates Effectiveness of Software Testing · Product Readiness and Deployment
Case Study
Global Retail Inc. is launching a new cloud-native loyalty rewards application. The application consists of multiple microservices running in containers, an API Gateway, and a NoSQL database. The DevOps team has a highly automated CI/CD pipeline that deploys changes to production multiple times per day. The application is in its final testing phase before the go-live date in one month.
Architecture Overview:
graph TD User[Mobile App User] --> AG[API Gateway] subgraph Kubernetes Cluster AG --> AuthSvc[Authentication Service] AG --> ProfileSvc[Profile Service] AG --> PointsSvc[Points Service] end AuthSvc --> DB[(UserDB)] ProfileSvc --> DB PointsSvc --> DBSecurity Posture:
The security team has not been heavily involved in the development process. A last-minute external penetration test revealed several critical vulnerabilities, including insecure direct object references (IDOR) in the Profile Service API and a lack of rate limiting on the Authentication Service, making it vulnerable to credential stuffing attacks. The DevOps team has fixed the IDOR issue but is pushing back on implementing rate limiting, citing potential performance impacts and the tight deadline.Requirement:
The Head of Security needs to make a recommendation on whether to approve the application for release. The primary goal is to prevent a major security breach immediately following launch while acknowledging the business pressure to release on time.What is the most prudent recommendation the Head of Security should make?
Show answer & explanation
Correct answer: C
This is the best recommendation as it balances security risk with business needs. A credential stuffing attack is a high-impact threat. Blocking the release is disruptive, but ignoring the risk is negligent. Implementing rate limiting at the API Gateway is a common and effective compensating control that can be deployed quickly without code changes. This mitigates the immediate risk, allowing the release to proceed, while the formal plan ensures the root cause is addressed properly in the near future. This demonstrates a mature approach to risk management.
Ready for the real thing?
The full KEO1 simulator has every exam-style question, timed mode, and instant scoring.