ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During sprint planning, a development team wants to pull several open-source libraries from a public repository to speed delivery of a payment module. Based on SAFECode software assurance best-practice guidance, which approach most effectively reduces the risk of introducing insecure or malicious third-party components?
Scan every candidate library for known vulnerabilities and maintain ongoing monitoring and re-assessment as part of the project's secure supply-chain process.
Select only the most downloaded libraries in the repository, assuming high adoption indicates stronger community vetting.
Pin each dependency to a specific version in the build script so the code base never changes without explicit developer action.
Require that all third-party libraries carry an open-source license so their source code can be inspected if problems arise.
SAFECode recommends that organizations adopt a structured process for selecting and managing third-party software. This includes performing security scans of each component for known vulnerabilities before use, approving them through a defined governance process, and continuously monitoring them for newly disclosed issues during the product lifecycle. Simply locking versions, trusting popularity, or relying on open-source licensing alone does not adequately address hidden vulnerabilities or malicious code that may surface after initial selection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SAFECode, and why is it important in software assurance?
Open an interactive chat with Bash
Why is scanning and monitoring third-party libraries necessary?
Open an interactive chat with Bash
Why isn’t pinning dependency versions or relying on popularity enough to ensure security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .