ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While populating a release's SBOM, which single attribute is most essential for allowing automated scanners to determine whether a newly published CVE applies to a specific open-source library you shipped?
Repository URL where the component's source code is maintained
Cryptographic hash (e.g., SHA-256) of the component's binary artifact
SPDX license identifier associated with the component
Precise package name combined with its version string (for example, vendor/product 1.2.3)
Vulnerability databases such as the NVD list affected software as vendor/product name paired with an exact version identifier, commonly expressed through a CPE. Automated tools match those name-version strings against an SBOM to decide impact. Although hashes, license identifiers, and repository URLs provide integrity, compliance, or provenance information, they are not the primary key used for vulnerability correlation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SBOM?
Open an interactive chat with Bash
What is a CVE and how is it used with SBOMs?
Open an interactive chat with Bash
What role does the CPE play in vulnerability detection?
Open an interactive chat with Bash
What is an SBOM and why is it important?
Open an interactive chat with Bash
What is a CVE and how does it relate to software vulnerabilities?
Open an interactive chat with Bash
What is a CPE and how does it help in vulnerability management?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .