Practice CSSLP Secure Software Supply Chain questions with full explanations on every answer.
Start practicing
Secure Software Supply Chain — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are implementing a Software Bill of Materials (SBOM) using the CycloneDX standard for your CI/CD pipeline. Which of the following fields is mandatory to uniquely identify an individual component within the SBOM to ensure accurate vulnerability tracking?
2When evaluating a vendor's open-source usage, which factor is the strongest indicator of a proactive security posture?
3During a vendor security assessment, you require a supplier to provide proof that their software is signed. Which mechanism should you verify to ensure the code's integrity and origin authenticity?
4An organization is concerned about 'Typosquatting' in their build system. Which strategy is most effective at preventing the accidental inclusion of malicious, similarly-named packages?
5You are auditing a third-party vendor's CI/CD pipeline integration. You notice they pull dependencies from public mirrors without pinning them to specific hashes. What is the primary security risk here?
6Your organization uses a 'Golden Image' approach for build containers. To prevent supply chain contamination of these build environments, what is the most effective security control?
7You are setting up an automated policy in GitHub Actions to block builds that contain dependencies with known high-severity vulnerabilities. Which tool is standard for this type of automated gated check?
8Your development team is integrating a new third-party library via npm. To prevent dependency confusion attacks where a malicious package is pulled from a public registry instead of your internal private registry, which configuration should be applied?
9You are using 'in-toto' to secure your software supply chain. What is the primary purpose of a 'layout' file in this framework?
10What is the primary function of a 'Vulnerability Disclosure Policy' (VDP) in a vendor's secure development lifecycle?
11You notice that your build server environment pulls Docker images from a public registry with the ':latest' tag. Why is this a major supply chain security flaw?
12A supplier asks you to describe your 'Supply Chain Security Policy'. What is the most appropriate foundational element to include?
13When assessing a SaaS provider's supply chain, you are concerned about their 'Vendor Risk Management' (VRM) program. Which practice indicates a mature approach to fourth-party risk?
14An organization is adopting the SLSA (Supply-chain Levels for Software Artifacts) framework. To achieve Level 3, what requirement must be met regarding the build platform?
15When performing a vendor security assessment for a new SaaS product, which THREE of the following should be requested to evaluate their supply chain resilience?
16To protect against a compromised build pipeline, which TWO of the following configurations should be implemented to ensure 'Hermetic Builds'?
17Which THREE of the following are common threats to the Software Supply Chain that an SBOM can help mitigate?
18When designing an automated pipeline to prevent supply chain attacks, which THREE of the following features should be included in your artifact registry?
19Which TWO of the following are essential components of an effective Vendor Security Assessment program?
20To defend against 'Dependency Confusion' attacks, which TWO of the following configurations should you apply to your private package manager?
The Secure Software Supply Chain domain covers the key concepts tested in this area of the CSSLP exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CSSLP domains — no account required.
The Courseiva CSSLP question bank contains 20 questions in the Secure Software Supply Chain domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Secure Software Supply Chain domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included