ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
During sprint planning for a fintech application, the development team proposes adding a recently released open-source encryption library pulled directly from a public Git repository. To adhere to secure coding practices for trusted versus untrusted libraries, what should the security champion do first before approving its inclusion?
Encrypt all runtime communication between the application and the library using TLS to protect data in transit.
Store the library binaries on a read-only file system so they cannot be modified after deployment.
Run software composition analysis to verify the library's origin, license, and any published vulnerabilities before adding it to the codebase.
Compile the library with all available compiler security-hardening flags and proceed with integration.
Before any third-party component is introduced, it must be vetted for known security issues and provenance. Running a software composition analysis (SCA) or comparable dependency-checking process identifies publicly reported CVEs, verifies checksums or digital signatures to confirm the code came from the expected source, and confirms that the license is acceptable. Hardening compiler flags, storing binaries read-only, or encrypting runtime traffic may be useful later, but they do not establish whether the library is already vulnerable or malicious. Therefore, performing SCA and origin verification is the essential first step.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Software Composition Analysis (SCA)?
Open an interactive chat with Bash
What are CVEs and why are they important in software security?
Open an interactive chat with Bash
How does verifying the origin and authenticity of a library protect against security risks?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .