ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While vetting a newly added third-party JAR before integration, you run an entropy scan across its class files. Most files average 4-5 bits of entropy per byte, but one 70 KB class shows a uniform distribution near 8 bits per byte. From a secure code-review perspective, what risk does this anomaly most strongly suggest?
The class simply contains an efficient Bloom filter table generated at build time.
The file may hide a packed or encrypted malicious payload inserted by an attacker.
The compiler applied aggressive dead-code elimination, leaving random padding that increases entropy.
The library developer enabled standard Java bytecode obfuscation for intellectual-property protection.
Very high, almost-uniform entropy is typical of data that has been compressed with a strong packer or encrypted to conceal its contents. Attackers use these techniques to hide backdoors, logic bombs, or other malicious payloads so static inspection will not reveal their purpose. Ordinary bytecode, even if optimized or obfuscated, normally contains repetitive patterns and thus lower entropy scores (around 4-6 bits per byte). A Bloom filter implementation or dead code could exist, but they seldom drive entropy to the theoretical maximum across a large file. Therefore, the sharp entropy spike most plausibly signals a packed or encrypted component that warrants deeper examination-such as dynamic analysis or unpacking-to rule out hidden malware.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is entropy in the context of secure code review?
Open an interactive chat with Bash
How do attackers use packing or encryption to hide malicious payloads?
Open an interactive chat with Bash
Why wouldn’t standard bytecode obfuscation result in extremely high entropy like 8 bits per byte?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .