ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During component selection for a payment-processing application, a secure software engineer is evaluating an open-source cryptographic library. To ensure the component can be trusted for the full life of the product, which evaluation criterion should carry the MOST weight in the decision?
The project has an active community that rapidly addresses reported vulnerabilities and publishes regular updates.
The library's documented features align with the application's functional requirements.
The library is distributed under a permissive MIT open-source license.
The code is written entirely in a memory-safe programming language.
When choosing an open-source component, the engineer must look beyond whether it meets functional needs or has a permissive license. The critical security concern is whether the component will continue to receive timely patches and vulnerability fixes. An active, responsive maintainer community (or commercial support) is a strong indicator that newly discovered flaws will be addressed quickly, reducing long-term risk. A permissive license, memory-safe language, and feature fit are all important, but without sustained maintenance and vulnerability response, the component's security posture will rapidly degrade.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is an active community important for cryptographic libraries?
Open an interactive chat with Bash
What is a permissive MIT license, and why is it important?
Open an interactive chat with Bash
What makes a memory-safe programming language significant for security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .