ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization urgently needs an update and downloads a pre-compiled open-source library from an unofficial mirror. Before approving the component, which action most directly confirms its pedigree and provenance to ensure it originated unaltered from the legitimate supplier?
Compare the file's cryptographic hash with the maintainer's digitally signed checksum.
Deploy the library in a staging environment and monitor run-time behavior for a week.
Examine the library's license to confirm it allows commercial redistribution.
Run a static code analyzer to detect known weaknesses in the library.
Comparing the library's cryptographic hash to a checksum that has been digitally signed and published by the official project verifies both authenticity (the file came from the claimed source) and integrity (it has not been modified in transit). This practice establishes a chain of custody consistent with supply-chain guidance such as NIST SP 800-218. Static analysis, license review, and staged run-time monitoring are valuable for other forms of risk assessment, but they do not reliably prove where the binary came from or whether it was tampered with.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a cryptographic hash?
Open an interactive chat with Bash
How does a checksum ensure integrity?
Open an interactive chat with Bash
What is NIST SP 800-218?
Open an interactive chat with Bash
What is a cryptographic hash?
Open an interactive chat with Bash
What is a digitally signed checksum?
Open an interactive chat with Bash
What is NIST SP 800-218 supply-chain guidance?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Supply Chain
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .