ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your organization is about to purchase a third-party CRM package that will run on your internal servers. Before signing the purchase order, the security team wants assurance that the code does not contain outdated open-source libraries with known CVEs. Which action during the development/acquisition phase BEST meets this requirement?
Obtain a Software Bill of Materials from the vendor and run software composition analysis against it.
Review the vendor's end-user license agreement to confirm liability clauses.
Attend a live demonstration of the application's user interface in a sandbox environment.
Deploy the application to production and rely on intrusion detection rules during the first week.
Requesting an SBOM and performing software composition analysis directly targets the risk of vulnerable third-party components, allowing the security team to verify each library against public vulnerability databases before deployment. Merely reviewing the EULA, watching a product demo, or relying on post-deployment network monitoring may provide operational or contractual insight, but none proactively determines whether the code base already contains exploitable flaws.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Software Bill of Materials (SBOM)?
Open an interactive chat with Bash
What is a CVE, and why is it important in software security?
Open an interactive chat with Bash
What is software composition analysis (SCA)?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .