ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While assessing an open-source encryption library for inclusion in a regulated payment application, you review its origin and support details. Which single observation should raise the greatest concern about adopting the component from an origin-and-support standpoint, potentially outweighing other favorable factors and directing you to reject or further vet the library?
Releases are not cryptographically signed and are available only from a sole developer's personal GitHub repository.
The project has an active contributor mailing list and automated CI pipeline for pull requests.
The issue tracker lists several open security bugs with pending patches awaiting review.
The code is released under the permissive MIT open-source license.
Unsigned releases distributed only from a personal repository provide little assurance that the code you download is exactly what the developer published. Without a cryptographic signature or distribution through a trusted package registry, you cannot confirm authenticity or detect tampering, making provenance highly questionable. A permissive MIT license is common and not inherently risky, an active community and CI pipeline are positive indicators of support, and documented security bugs with patches waiting for review show engagement rather than neglect. Therefore, the lack of verifiable, signed releases from a trustworthy source is the most serious origin-and-support red flag.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is the absence of cryptographic signatures on software releases a major concern?
Open an interactive chat with Bash
What does a personal GitHub repository imply about software reliability and support?
Open an interactive chat with Bash
What is the significance of a permissive MIT open-source license compared to cryptographic origins?
Open an interactive chat with Bash
What is cryptographic signing and why is it important for software releases?
Open an interactive chat with Bash
What is a sole developer's repository, and why is it considered risky?
Open an interactive chat with Bash
How does the MIT license affect the security of open-source software?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .