ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

A software security engineer is assessing an open-source JSON library for a healthcare application. Scanning identifies a critical deserialization CVE with publicly available exploits, but a patched release is already available. The library is actively maintained and distributed under the permissive JSON License. Which risk treatment is MOST appropriate before approving the component?

  • Avoid the risk entirely by rewriting the JSON parsing functionality in-house and eliminating the dependency.

  • Transfer the risk by requiring the cloud hosting provider to monitor and patch the library on your behalf.

  • Accept the risk because the vulnerability is documented and the library's license is permissive.

  • Mitigate the risk by upgrading to the patched version and verifying the vulnerability is resolved before deployment.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot