The correct answer is not validating digital signatures of downloaded components. Digital signatures verify the authenticity and integrity of software components, confirming they come from the expected source and haven't been tampered with. Failing to validate these signatures creates risk of supply chain attacks where malicious code is disguised as legitimate components.
Bypassing vulnerability scanning during the integration pipeline for approved vendors introduces significant risk by assuming that trusted vendors never distribute vulnerable components. This practice could allow known vulnerabilities to be integrated into the application without detection, but it's not as severe as completely failing to verify the authenticity of components.
Using dynamically linked libraries instead of statically compiled dependencies is an architectural choice with security implications but isn't inherently a high-risk practice. While dynamic linking can introduce dependency confusion risks and version compatibility issues, modern dependency management typically addresses these concerns and provides benefits like easier patching.
Implementing just-in-time component fetching during production deployment involves retrieving dependencies at runtime rather than bundling them with the application. This approach can introduce availability risks and potential supply chain attacks if components change between testing and production use, but properly implemented verification mechanisms can mitigate these risks.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is validating digital signatures for third-party components crucial?
Open an interactive chat with Bash
What is a supply chain attack, and how does it relate to third-party components?
Open an interactive chat with Bash
What are some best practices for securing third-party software integration?
Open an interactive chat with Bash
ISC2 CISSP
Software Development Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .