ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your DevSecOps team is adding software composition analysis (SCA) to its Git-based CI/CD pipeline for a Node.js microservice. The goal is to block introduction of vulnerable open-source libraries as early as possible while minimizing wasted build time. At which pipeline point should the SCA scan be executed?
Only when a critical vulnerability is announced by an external advisory service
As a pre-commit or pre-merge job that runs immediately after a developer pushes code to the shared repository
After the application is deployed to production, triggered by the first user request
As part of the long-running performance test stage executed nightly on the staging environment
SCA tools are most effective when they run as early as feasible to detect known-vulnerable third-party components before they become deeply embedded in the build. Executing SCA immediately after the developer pushes code (for example, as a pre-commit or pre-merge job) supports the shift-left principle, prevents vulnerable dependencies from entering the shared code base, and avoids wasting subsequent build, test, and deployment resources. Running SCA only during lengthy performance tests, after production deployment, or conditionally on external advisories all delays detection, increases remediation cost, and risks exposing users to vulnerable code.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is software composition analysis (SCA)?
Open an interactive chat with Bash
What does the 'shift-left principle' mean in DevSecOps?
Open an interactive chat with Bash
Why is it important to scan for vulnerabilities before code reaches the shared repository?
Open an interactive chat with Bash
What is software composition analysis (SCA)?
Open an interactive chat with Bash
What does 'shift-left' mean in DevSecOps?
Open an interactive chat with Bash
How does pre-commit or pre-merge SCA reduce risks in CI/CD pipelines?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .