ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an internal risk review you learn that the organization's CI/CD platform could be compromised, allowing attackers to inject malicious code at build time. Which safeguard within the build environment provides the strongest assurance of artifact integrity and provenance?
Run static application security testing (SAST) tools after each compilation is complete.
Require the build system to create cryptographically signed software provenance attestations (e.g., in-toto or SLSA) for every build artifact.
Limit access to the build server by enforcing strict role-based file permissions.
Mandate multi-factor authentication for all developers accessing the source code repository.
Generating a cryptographically signed provenance attestation (for example, using the in-toto or SLSA framework) records exactly which source files, dependencies, and build steps produced each artifact and binds that information to a digital signature created inside the trusted build system. Anyone later receiving the binary can verify the signature and compare the recorded metadata to expected values, detecting any tampering of code or build process. File permissions, post-build static analysis, and multifactor access to source control are valuable controls, but none create an immutable, verifiable chain of custody for the resulting binaries, so they cannot independently guarantee provenance or integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is in-toto?
Open an interactive chat with Bash
What is SLSA in the context of secure software development?
Open an interactive chat with Bash
Why is cryptographic signing critical for build artifact integrity?
Open an interactive chat with Bash
What is software provenance?
Open an interactive chat with Bash
How does cryptographic signing ensure integrity in the build system?
Open an interactive chat with Bash
What are in-toto and SLSA frameworks?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .