ISC2 CISSP Practice Question

A lead security architect at a financial services company is reviewing the firm's new DevSecOps strategy. The strategy encourages developers to leverage open-source components from public repositories to accelerate development. While this approach has benefits, the architect is tasked with identifying the most significant, high-impact security threat to prioritize for mitigation. Which of the following represents the PRIMARY security concern the architect should highlight to leadership regarding the use of these public code repositories?

  • The potential for dependency confusion attacks targeting internal packages

  • The risk of embedding components with deliberately obfuscated vulnerabilities

  • The lack of formal security assurance processes for contributed code

  • The potential for repository infrastructures to be compromised to distribute malicious code

ISC2 CISSP
Software Development Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot