ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
A DevSecOps team has configured their CI pipeline to run SAST and software-composition scans that assign CVSS scores to every finding. Tonight's build finishes with the following results: one vulnerability scored 9.8 (critical), two scored 6.3-6.5 (medium), and several lows. According to commonly accepted break/build criteria based on severity, what should the pipeline do with this build?
Allow the build to continue but log a ticket so the critical issue is addressed in the next sprint.
Fail the build immediately and block promotion until the critical vulnerability is fixed or mitigated.
Pause the pipeline and wait for the security team to manually evaluate every finding before deciding.
Promote the build because the total number of vulnerabilities is small and only one is critical.
Industry guidance such as the NIST Secure Software Development Framework and OWASP DevSecOps practices recommends establishing objective thresholds that automatically fail a build when any critical or high-severity vulnerability is detected. Allowing promotion with known critical flaws places the organization at unacceptable risk, regardless of how few total findings exist. Medium or low issues can be tracked for timely remediation, but they do not normally block the build unless the policy expressly says so. Waiting for a manual review undermines the reliability and repeatability of automated controls that break the build on severe findings.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CI pipeline in DevSecOps?
Open an interactive chat with Bash
What is a CVSS score?
Open an interactive chat with Bash
Why does industry guidance recommend automated break/build criteria for critical vulnerabilities?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Testing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .