ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization's CI/CD pipeline automatically downloads open-source libraries from a public repository during each build. To satisfy pedigree and provenance requirements, the pipeline must halt if a component's authenticity and integrity cannot be proven. Which control most directly fulfills this need?
Run quarterly vulnerability scans against the container images produced by the build.
Require developers to manually acknowledge the component's license in each pull request.
Verify the repository's digital signatures and cryptographic hashes for every downloaded artifact before the build proceeds.
Maintain an internal spreadsheet that lists approved component versions.
Cryptographic signatures and file hashes allow the build system to verify both authenticity (the artifact was signed with a trusted publisher key) and integrity (the bits have not changed since signing). By configuring the pipeline to check each artifact's digital signature and compare its cryptographic hash to a trusted value before compilation, any tampered or spoofed component will fail the gate and stop the build. License acknowledgements, periodic vulnerability scans, and inventory spreadsheets are useful for compliance or vulnerability management, but they do not provide the real-time cryptographic proof of origin and integrity needed to enforce provenance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are cryptographic signatures?
Open an interactive chat with Bash
What is the difference between authenticity and integrity in cryptographic terms?
Open an interactive chat with Bash
How do cryptographic hashes work in verifying files?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .