ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your firm is selecting a third-party encryption library. As part of due diligence, you must evaluate each supplier's security track record to reduce risk in the software supply chain. Which of the following pieces of evidence would be the most persuasive demonstration of a mature, trustworthy security track record?
A recent SOC 1 Type II report that attests to the supplier's financial reporting controls.
A glossy vendor brochure asserting that the library uses "military-grade" encryption algorithms.
A public history showing that all reported CVEs for the product have been disclosed and patched within 30 days over the past three years.
An independent penetration-test report from five years ago that found no critical vulnerabilities at that time.
A well-documented record of promptly disclosed vulnerabilities that are assigned CVE identifiers and fixed within an industry-standard remediation window demonstrates that the supplier both detects and corrects security issues in a disciplined, transparent manner. Timely patch release and public disclosure are key indicators of a mature secure development and vulnerability-management process, points specifically called out in supply-chain guidance such as NIST SP 800-218 and SP 800-161. Marketing claims without verification, audit reports that address only financial controls, or a single outdated penetration test do not give ongoing, security-specific evidence of how a supplier handles vulnerabilities over time, so they are weaker indicators of a current security track record.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a CVE, and why is it important for evaluating a product's security record?
Open an interactive chat with Bash
What is the significance of NIST SP 800-218 and SP 800-161 in software supply chain security?
Open an interactive chat with Bash
Why are timely vulnerability disclosures and patches critical in the software supply chain?
Open an interactive chat with Bash
What is a CVE, and why are they important?
Open an interactive chat with Bash
What is the significance of the 30-day patch window mentioned in the answer?
Open an interactive chat with Bash
What are NIST SP 800-218 and SP 800-161, and how do they relate to software supply chain security?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .