ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization's CI/CD pipeline automatically retrieves open-source libraries from public package repositories. To satisfy third-party vendor security requirements, which control MOST effectively assures the integrity of each library before it is introduced into the build environment?
Require developers to manually review the library's source code for insecure functions
Run dynamic application security tests after the application is compiled with the library
Validate the library's digital signature or cryptographic hash against an authoritative source before use
Allow only libraries released within the last 30 days and specified with pinned version numbers
Verifying a package's digital signature or cryptographic hash confirms that the exact code published by the trusted source is what is being built, preventing tampering or repo-poisoning attacks. Dynamic testing, manual code reviews, and version pinning are valuable practices, but none directly guarantee that the component was not altered in transit or in the repository. Integrity verification with signatures or hashes is therefore the most appropriate requirement for protecting the supply chain at the point of acquisition.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a digital signature and how does it confirm the integrity of a library?
Open an interactive chat with Bash
How does cryptographic hashing help verify a library's integrity?
Open an interactive chat with Bash
What are repo-poisoning attacks and how does integrity verification mitigate them?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Requirements
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .