ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your development team uses several open-source libraries pulled from a public package repository. After the initial security review is complete, which ongoing action best supports secure-coding practice for vetting and monitoring these external components throughout the product lifecycle?
Rely on project maintainer release notes and update libraries only when new features are needed.
Lock all dependency versions in build files and disable update checks to avoid unexpected changes.
Integrate an automated software composition analysis service into the CI/CD pipeline to flag newly disclosed vulnerabilities in dependency versions.
Conduct a manual license compliance review of each library once during every major release cycle.
Continuous monitoring is essential because new vulnerabilities are discovered in third-party code after release. Integrating an automated software composition analysis (SCA) tool into the CI/CD pipeline ensures every build is checked against up-to-date vulnerability feeds (e.g., NVD). This provides timely alerts when a newly published CVE affects a dependency so the team can patch or upgrade quickly. Simply pinning versions without checks, limiting reviews to infrequent manual license audits, or waiting for maintainers to announce new features leaves the application exposed to emerging security flaws.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SCA tool and how does it work?
Open an interactive chat with Bash
What is the CI/CD pipeline's role in secure software development?
Open an interactive chat with Bash
What is the National Vulnerability Database (NVD) and its relevance to SCA tools?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .