ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your DevSecOps team maintains a cloud-native application that relies on dozens of open-source libraries. Policy mandates vulnerabilities in third-party components be discovered and remediated within 48 hours of disclosure. When revising the CI/CD pipeline, which measure will best satisfy this continuous monitoring requirement?
Integrate an automated software composition analysis tool that scans dependencies during every build and cross-checks them against public vulnerability databases.
Require developers to manually search for new CVEs affecting each dependency before every major release.
Schedule quarterly manual penetration tests that emphasize third-party code paths.
Maintain a spreadsheet-based SBOM that is updated after each production deployment.
Automated software composition analysis (SCA) tools integrate with the build pipeline, generate or reference the project's SBOM, and query vulnerability feeds such as the NVD or OSS-Index on every commit or build. This provides near-real-time identification of newly published CVEs that affect included libraries, enabling response well inside the 48-hour window. Manual penetration tests are too infrequent, spreadsheets do not actively flag new CVEs, and asking developers to perform ad-hoc CVE searches is error-prone and cannot guarantee continuous monitoring.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SBOM and why is it important?
Open an interactive chat with Bash
How does an automated Software Composition Analysis (SCA) tool work?
Open an interactive chat with Bash
What is a CVE and how does it relate to application security?
Open an interactive chat with Bash
What is a Software Composition Analysis (SCA) tool?
Open an interactive chat with Bash
What is an SBOM and why is it important?
Open an interactive chat with Bash
What are CVEs, and why are they relevant to software security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .