ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your DevSecOps team must ensure the software bill of materials (SBOM) for a microservice stays accurate as developers add or upgrade open-source libraries. Which practice best automates the detection of new components and immediately records them in the SBOM so risk can be reassessed on every change?
Have the legal team perform a manual license and component review at the end of each quarter.
Rely on container image vulnerability scans that execute only after deployment to production.
Ask developers to update a shared spreadsheet of third-party libraries before each formal release.
Run a software composition analysis step in the CI pipeline that rebuilds the SBOM on every commit or merge.
Integrating a software composition analysis (SCA) tool into the continuous integration (CI) pipeline causes each build to be scanned automatically. The scanner inventories all direct and transitive dependencies, regenerates or updates the SBOM, and flags newly introduced or changed components for vulnerability review. Quarterly manual reviews or relying on production-time image scans and spreadsheets are periodic or after-the-fact controls; they do not keep the SBOM continuously current with every code change.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
How does Software Composition Analysis (SCA) work in a CI Pipeline?
Open an interactive chat with Bash
Why is it important to regenerate the SBOM with every code change?
Open an interactive chat with Bash
What is a Software Composition Analysis (SCA) tool?
Open an interactive chat with Bash
What is the Software Bill of Materials (SBOM) and why is it important?
Open an interactive chat with Bash
How does integrating an SCA into the CI pipeline benefit secure development?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .