ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While conducting threat modeling for a new e-commerce platform, you learn the developers plan to integrate an open-source payment-tokenization library downloaded directly from a public Git repository. Which risk inherited from a third-party supplier should you flag as the MOST relevant security threat?
Its MIT license might require the company to include attribution text in product documentation.
The library may already contain vulnerabilities or malicious code introduced upstream, enabling attackers to compromise payment data or inject backdoors.
Adding the library could increase the application's download size, slowing page loads for mobile users.
Ongoing maintenance of the library could cease, forcing the development team to rewrite payment functionality in the future.
Because the team is obtaining code that is created and maintained outside the organization, the primary security concern is that the library could already contain exploitable vulnerabilities or intentionally malicious code, or that an attacker could tamper with the library's update channel. Such weaknesses would let an adversary compromise the application and expose sensitive payment data. Lack of future support is a maintainability problem, not an immediate security threat. License obligations are a legal/compliance issue rather than a security flaw. Larger bundle size affects performance and user experience but does not directly threaten confidentiality, integrity, or availability. Therefore, the threat of vulnerable or malicious third-party code is the most significant security risk to capture in the model.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is payment-tokenization and why is it important in e-commerce?
Open an interactive chat with Bash
What security risks are associated with using open-source libraries in software development?
Open an interactive chat with Bash
What is an MIT license and why is it less critical compared to security issues?
Open an interactive chat with Bash
How can developers verify the security of an open-source library before integration?
Open an interactive chat with Bash
What is payment tokenization, and how does it contribute to security?
Open an interactive chat with Bash
What steps can be taken to mitigate risks from upstream vulnerabilities in third-party libraries?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .