Courseiva
hardMultiple Choice

CCSP Practice Question: Uses a private artifact registry for approved…

An organization uses a private artifact registry for approved packages. What attack does this practice primarily defend against?

⚠ Common exam trap

CCSP often tests the distinction between supply chain attacks that target package resolution (dependency confusion) and those that target the package contents themselves (typosquatting, malicious commits), so candidates must read the scenario carefully to identify which mechanism is being defended.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dependency confusion attacks

A private artifact registry restricts package resolution to a curated, organization-controlled source, so an attacker cannot trick the build system into pulling a malicious package with the same name from a public repository. Dependency confusion exploits the fact that public registries are often checked before or alongside private ones, allowing a higher-versioned public package to override the internal one. By using only a private registry, the organization removes that public lookup path entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Dependency confusion attacks

    Why this is correct

    A private artifact registry restricts package resolution to vetted internal sources, so a malicious public package sharing a name with an internal dependency cannot be pulled in. This directly neutralises dependency confusion, where attackers publish higher-versioned public packages to hijack internal build resolution.

  • ✗

    Denial of service attacks

    Why it's wrong here

    Denial of service attacks overwhelm availability through traffic volume or resource exhaustion, which a private artifact registry does not mitigate; it controls package provenance, not request rates. Registries defend against malicious or unapproved dependencies entering the build pipeline, not volumetric flooding.

  • ✗

    Man-in-the-middle attacks

    Why it's wrong here

    A private registry restricts package sources to vetted artefacts, so it does not address interception of traffic in transit. Man-in-the-middle attacks are countered by TLS, certificate pinning and signed packages, which protect integrity and authenticity on untrusted networks. A private registry would be the right control when the risk is dependency confusion or typosquatting.

  • ✗

    Injection attacks

    Why it's wrong here

    A private artifact registry restricts which packages can be pulled, addressing supply-chain and typosquatting risks from untrusted public repositories. Injection attacks exploit unvalidated input at runtime, such as SQL or command injection, which registry curation does nothing to prevent.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.