Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: An attacker publishes a malicious package to a…

An attacker publishes a malicious package to a public registry using the same name as an internal package used by a cloud application. This attack is known as:

⚠ Common exam trap

The CCSP exam often tests the distinction between dependency confusion and typosquatting, so the trap here is that candidates confuse the exact-name-match technique (dependency confusion) with the misspelling-based technique (typosquatting), leading them to incorrectly select typosquatting when the question explicitly states 'same name.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Dependency confusion

Dependency confusion occurs when an attacker publishes a malicious package to a public registry (e.g., npm, PyPI, Maven Central) using the same name as an internal, private package. When a cloud application's build system is configured to fetch dependencies from both public and private registries, the package manager may prioritize the public registry (often due to higher version numbers or default resolution order), causing the malicious package to be installed instead of the legitimate internal one. This exploits the trust in package resolution algorithms and is a specific form of supply chain attack targeting cloud-native CI/CD pipelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Dependency confusion

    Why this is correct

    Dependency confusion exploits package resolution order to install a malicious public package.

  • Supply chain poisoning

    Why it's wrong here

    Supply chain poisoning is a broader term.

  • Man-in-the-middle attack

    Why it's wrong here

    MITM intercepts communications.

  • Typosquatting

    Why it's wrong here

    Typosquatting uses similar names to trick users.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.