hardMultiple Choice
CCSP Practice Question: A company uses a private artifact registry for…
A company uses a private artifact registry for internal packages. An attacker publishes a malicious package with the same name as an internal package to a public registry. Which attack is being described?
⚠ Common exam trap
The ISC2 CCSP exam often tests the distinction between 'dependency confusion' and 'supply chain poisoning', but dependency confusion is a specific subtype where the attacker exploits name collision between public and private registries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dependency confusion attack
This is a dependency confusion attack, where an attacker uploads a malicious package to a public registry (e.g., npm, PyPI, Maven Central) using the same name as a private package used internally by the target organization. When a build system or developer's package manager is configured to check public registries first (or as a fallback), it may download the attacker's malicious version instead of the legitimate internal package, leading to code execution or data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dependency confusion attack
Why this is correct
Dependency confusion exploits a resolver's preference for public registries over private ones. When a package name exists in both, the build tool fetches the attacker's higher-versioned public copy, executing malicious code. This matches the stem's scenario: identical internal and public package names, enabling supply-chain compromise.
- ✗
Supply chain poisoning
Why it's wrong here
Supply chain poisoning compromises a legitimate dependency or its build pipeline, so trusted artefacts arrive already tainted. This scenario involves no compromise of the genuine internal package; the attacker instead exploits namespace resolution by publishing a same-named package publicly. Supply chain poisoning would fit if the internal registry or its upstream dependency were itself breached.
- ✗
Typosquatting
Why it's wrong here
Typosquatting relies on a misspelt or visually similar name that a user mistypes, such as 'examp1e' instead of 'example'. Here the public package carries the identical name, not a lookalike, so the mechanism is dependency confusion rather than typographical deception. Typosquatting would be correct if the attacker registered a near-miss spelling.
- ✗
Man-in-the-middle attack
Why it's wrong here
A man-in-the-middle attack intercepts an existing communication session between two parties, requiring the attacker to position themselves within the traffic path. Here no session is intercepted; the attacker instead exploits name resolution to substitute a package. MitM suits scenarios such as unencrypted Wi-Fi eavesdropping or TLS interception, not registry namespace abuse.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.