ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your DevSecOps team is about to configure an automated pipeline that pulls container images from a third-party vendor registry and deploys them directly into your cloud production cluster. Before approving this persistent system-to-system interconnection, which control will best verify the pedigree and provenance of every image obtained from the supplier?
Require the vendor to host its registry within the same cloud region as your production cluster to avoid cross-region transit.
Add the vendor's registry domain to the cluster's allow list and rely on TLS to encrypt traffic in transit.
Validate each image's cryptographic signature and checksum against a vendor-provided, signed software bill of materials prior to deployment.
Schedule automated vulnerability scans to run hourly on all containers after they are running in production.
Verifying pedigree and provenance focuses on confirming both the origin and the integrity of software before it is trusted inside an organization's environment. Requiring the vendor to supply a signed software bill of materials (SBOM) and cryptographically signing each container image allows your team to validate hashes and signatures during the pipeline's pull phase. This ensures the image truly comes from the expected source and has not been altered in transit or in the vendor's repository. Post-deployment vulnerability scans, regional placement, or simple network allow lists may mitigate other risks (exposure, latency, or confidentiality), but they do not positively establish the chain of custody or authenticity of the software itself, which is the core objective when verifying pedigree and provenance prior to interconnection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
How does cryptographic signing verify software integrity?
Open an interactive chat with Bash
Why are vulnerability scans not sufficient for pedigree verification?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .