ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization must select an open-source cryptographic library for a safety-critical embedded system. To align with NIST SSDF supply chain risk management practices, which FIRST requirement will best ensure you can confirm the library's integrity and provenance throughout its lifecycle?
Perform static application security testing (SAST) on the library before every production release.
Automatically pull the latest code from the supplier's public Git repository over HTTPS at build time.
Obtain a signed attestation from the supplier claiming compliance with ISO/IEC 27001 controls.
Require the supplier to deliver a complete SBOM that lists each file and its cryptographic hash value.
A software bill of materials (SBOM) that includes cryptographic hashes of every component establishes a definitive inventory and provides a technical means to verify integrity and origin whenever the library is obtained or updated. Static code analysis improves code quality but does not continuously prove provenance. A supplier's attestation letter offers no cryptographic assurance. Pulling code directly from a public repository, even over HTTPS, leaves the build process vulnerable to unnoticed tampering because the content is not independently verified.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SBOM and why is it important?
Open an interactive chat with Bash
How do cryptographic hashes verify integrity?
Open an interactive chat with Bash
What is NIST SSDF supply chain risk management?
Open an interactive chat with Bash
What is an SBOM and why is it important in supply chain security?
Open an interactive chat with Bash
How do cryptographic hashes ensure the integrity of a library over time?
Open an interactive chat with Bash
What are NIST SSDF guidelines for supply chain risk management?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .