ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization is selecting a popular open-source JSON parsing library to integrate into a payment processing microservice. To align with NIST's Secure Software Development Framework (SSDF) and minimize software supply chain risk, which action should you perform before allowing developers to import the library into the build pipeline?
Conduct a structured risk assessment that scans the library for known vulnerabilities and reviews its maintenance and patch history.
Add the library to the project's software bill of materials (SBOM) and postpone vulnerability scanning until after deployment.
Approve the library as long as its open-source license permits commercial use, deferring security considerations to later sprints.
Rely on the application firewall to filter any attacks that could exploit weaknesses in the library once it is deployed.
NIST SP 800-218 (SSDF) recommends that organizations identify and assess all third-party software components prior to use (practice PW.4). A risk assessment that includes scanning the candidate component for known vulnerabilities, evaluating its patch history, and confirming active maintenance helps determine whether the library's security posture is acceptable. Simply listing the library in an SBOM without prior analysis, relying on license terms alone, or deferring protection to a downstream control like a web application firewall overlooks the proactive due-diligence step required to manage supply-chain risk effectively.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the NIST Secure Software Development Framework (SSDF)?
Open an interactive chat with Bash
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
Why is it important to scan for vulnerabilities before integrating third-party libraries?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .