ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During an internal security audit of your organization's newly released web service, auditors find that several transitive open-source libraries were missed by the vulnerability scanner because they were never documented. To better manage this risk going forward, which action best aligns with NIST's Secure Software Development Framework recommendations?
Produce and maintain a software bill of materials that enumerates all direct and transitive components for each build.
Configure the vulnerability scanner to ignore transitive dependencies to prevent excessive false positives.
Mandate replacement of open-source libraries with proprietary alternatives that include commercial support contracts.
Postpone deployment of any release until every included component possesses ISO/IEC 27001 certification.
NIST SP 800-218 (SSDF) calls for organizations to identify and document every external software dependency-including transitive libraries-so they can be tracked for licensing and vulnerability exposure (practice PO.3.2). Generating and continuously maintaining a software bill of materials (SBOM) satisfies this requirement and enables scanners and other tools to recognize all components in every build. Simply preferring proprietary code, suppressing transitive findings, or demanding ISO/IEC 27001 certificates does not address the core problem of missing component visibility or align with the SSDF supply-chain controls.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
What are transitive dependencies and why are they important?
Open an interactive chat with Bash
How does NIST SP 800-218 recommend managing software dependencies?
Open an interactive chat with Bash
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
What are transitive dependencies, and why are they important?
Open an interactive chat with Bash
What is NIST SP 800-218 (SSDF), and how does it apply to managing open-source libraries?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .