ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization plans to allow a newly acquired analytics platform to pull sensitive customer data directly from your production database via an API-to-API connection. Which risk should you highlight as most critical during the pedigree and provenance review of this interconnection scenario?
Open-source components in the platform might have licenses incompatible with yours.
The third-party environment may be less secure, creating a new attack vector into the production database.
The real-time data exchange could increase network latency and slow analytics processing.
Differences in data serialization formats could require additional transformation logic.
The most critical risk is that the analytics platform could provide an additional attack path into the production database if its own security posture is weaker than the organization's. When systems are directly interconnected, a compromise of the third-party system can be leveraged to reach internal assets, leading to data breaches or manipulation. While the other concerns-data format mismatch, license incompatibility, and performance overhead-may cause operational or legal issues, they do not pose as immediate or severe a threat to the confidentiality and integrity of sensitive customer data as an expanded attack surface created by a less-secure partner system.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is meant by 'pedigree and provenance review'?
Open an interactive chat with Bash
Why does a less-secure third-party environment create a critical risk?
Open an interactive chat with Bash
How can an organization mitigate risks associated with API-to-API interconnections?
Open an interactive chat with Bash
What is pedigree and provenance review in system interconnections?
Open an interactive chat with Bash
Why is the third-party security posture critical in API-to-API connections?
Open an interactive chat with Bash
What steps can organizations take to mitigate risks with third-party API connections?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .