ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

While evaluating a cryptographic library for a payment system, the team must decide between a popular community-supported open-source package and a proprietary library backed by a vendor with a service-level agreement (SLA). Which risk is uniquely higher for the community-supported option when compared with the commercially licensed and supported alternative?

  • Acquisition costs could unexpectedly exceed the allocated licensing budget.

  • Engineers must compile source updates themselves, increasing deployment effort.

  • There is no contractual obligation ensuring that security patches will be delivered within an agreed timeline.

  • Attackers can study publicly available source code to find exploitable flaws.

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot