ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During a security review of your organization's automated build pipeline, you must recommend a control that most directly reduces the risk that malicious code or tooling can persist in the build environment and infect subsequent releases. Which approach BEST addresses this threat?
Spin up isolated, ephemeral build servers from a hardened, trusted image for every build and terminate them when the job completes.
Require all developers to sign Git commits with personal PGP keys before pushing to the central repository.
Perform vulnerability scanning of production servers on a monthly schedule and patch promptly.
Apply role-based access control to the cloud management console while continuing to use long-lived shared build servers.
Using disposable, isolated build servers that are instantiated from a trusted, version-controlled image for each build and destroyed immediately afterward eliminates any persistent state an attacker could leverage. Even if a compromise occurs during one job, the next build starts in a clean environment, preventing hidden malware or altered compilers from surviving. Developer commit signing improves code provenance but does not protect the build host itself. Scanning production servers or tightening cloud console permissions are valuable practices, yet they do not directly mitigate the risk of tampering within the build environment where binaries are produced.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an ephemeral build server?
Open an interactive chat with Bash
Why is using a hardened, trusted image crucial for security in build environments?
Open an interactive chat with Bash
How does destroying build servers after job completion reduce security risks?
Open an interactive chat with Bash
Why is using disposable, isolated build servers essential in secure build environments?
Open an interactive chat with Bash
What is a 'trusted image' and how is it maintained?
Open an interactive chat with Bash
How does ephemeral infrastructure contribute to security in CI/CD pipelines?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .