hardMultiple Choice
CCSP Practice Question: Uses a private artifact registry for approved…
An organization uses a private artifact registry for approved packages. What attack does this practice primarily defend against?
⚠ Common exam trap
CCSP often tests the distinction between supply chain attacks that target package resolution (dependency confusion) and those that target the package contents themselves (typosquatting, malicious commits), so candidates must read the scenario carefully to identify which mechanism is being defended.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dependency confusion attacks
A private artifact registry restricts package resolution to a curated, organization-controlled source, so an attacker cannot trick the build system into pulling a malicious package with the same name from a public repository. Dependency confusion exploits the fact that public registries are often checked before or alongside private ones, allowing a higher-versioned public package to override the internal one. By using only a private registry, the organization removes that public lookup path entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dependency confusion attacks
Why this is correct
A private artifact registry restricts package resolution to vetted internal sources, so a malicious public package sharing a name with an internal dependency cannot be pulled in. This directly neutralises dependency confusion, where attackers publish higher-versioned public packages to hijack internal build resolution.
- ✗
Denial of service attacks
Why it's wrong here
Denial of service attacks overwhelm availability through traffic volume or resource exhaustion, which a private artifact registry does not mitigate; it controls package provenance, not request rates. Registries defend against malicious or unapproved dependencies entering the build pipeline, not volumetric flooding.
- ✗
Man-in-the-middle attacks
Why it's wrong here
A private registry restricts package sources to vetted artefacts, so it does not address interception of traffic in transit. Man-in-the-middle attacks are countered by TLS, certificate pinning and signed packages, which protect integrity and authenticity on untrusted networks. A private registry would be the right control when the risk is dependency confusion or typosquatting.
- ✗
Injection attacks
Why it's wrong here
A private artifact registry restricts which packages can be pulled, addressing supply-chain and typosquatting risks from untrusted public repositories. Injection attacks exploit unvalidated input at runtime, such as SQL or command injection, which registry curation does nothing to prevent.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.