ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During acceptance testing, a developer must confirm that a third-party library pulled from an external repository is authentic and unaltered before it is placed in the build pipeline. Which approach most directly achieves both goals?
Review the component's file size and modification date in the repository, then run an antivirus scan before packaging.
Validate the supplier's digital signature on the library and compare its SHA-256 hash to the value recorded in the SBOM.
Download the component over HTTPS and store it in a write-once media repository for later auditing.
Compute an MD5 hash of the installed file after deployment and compare it with a baseline stored on the production host.
Verifying the supplier's digital signature provides cryptographic proof that the component came from the claimed publisher (authenticity). Independently calculating a strong hash such as SHA-256 and comparing it with the value published in the project's SBOM confirms that no bits changed from the time the supplier signed it (integrity). Relying on MD5 after deployment only checks integrity with a weak algorithm and offers no origin assurance. Transport encryption (HTTPS) or immutable storage helps protect the file in transit or at rest but does not establish provenance. File attributes and antivirus scans are useful hygiene steps yet cannot cryptographically prove authenticity or integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a digital signature and how does it prove authenticity?
Open an interactive chat with Bash
What is SHA-256 and why is it used for integrity checks?
Open an interactive chat with Bash
What is an SBOM and how does it aid in validating a library's security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .