ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During a sprint review you learn that a developer copied source files for an open-source JSON parser from a public GitHub gist into the project repository to avoid adding a formal dependency. From a secure code reuse perspective, what is the most appropriate response?

  • Replace the copied code with the project's vetted package and manage it through the organization's repository so it is automatically tracked by software composition analysis.

  • Retain the copied code and obfuscate it so attackers cannot easily understand or exploit it.

  • Keep the copied files but perform a one-time static analysis scan before the next release.

  • Accept the change because eliminating external dependencies reduces supply-chain risk and simplifies builds.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot