CISSP Software Development Security Practice Question
A security engineer is evaluating a new third-party software component for use in a critical application. Which document is most important to review to understand the component's supply chain security?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software Bill of Materials (SBOM)
A Software Bill of Materials (SBOM) lists all components, libraries, and dependencies used in the software. It is essential for assessing supply chain risk and identifying known vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
End User License Agreement (EULA)
Why it's wrong here
An End User License Agreement (EULA) is a legal contract between the software developer or publisher and the end user, outlining the terms and conditions for using the software. It primarily addresses licensing rights, restrictions on copying or modification, and disclaimers of warranty. A EULA does not provide any technical details about the software's internal components, dependencies, or potential security vulnerabilities, making it unsuitable for a security evaluation of its constituent parts.
- ✗
Service Level Agreement (SLA)
Why it's wrong here
A Service Level Agreement (SLA) is a contractual agreement between a service provider and a customer that defines the level of service expected, including metrics for uptime, performance, and support response times. While crucial for operational reliability, an SLA focuses on the delivery and availability of the service, not the underlying software's internal composition. Therefore, it offers no insight into the third-party components used or their associated security risks, which is essential for a security engineer evaluating the software itself.
- ✗
Data Processing Agreement (DPA)
Why it's wrong here
A Data Processing Agreement (DPA) is a legally binding contract that specifies the rights and obligations of both the data controller and the data processor regarding the handling of personal data. Its primary purpose is to ensure compliance with data protection regulations like GDPR or CCPA by detailing how data will be collected, stored, processed, and secured from a privacy perspective. A DPA does not, however, provide an inventory of the software's constituent components or libraries, which is what a security engineer needs to assess supply chain vulnerabilities.
- ✓
Software Bill of Materials (SBOM)
Why this is correct
A Software Bill of Materials (SBOM) is a formal, machine-readable inventory of all the software components and dependencies used in a particular application, including open-source and commercial libraries. It provides a comprehensive list of ingredients, their versions, and often their licenses, offering crucial transparency into the software's supply chain. For a security engineer, an SBOM is invaluable for identifying potential vulnerabilities, tracking known exploits (like Log4Shell), and managing risks associated with third-party components, making it the ideal tool for evaluating new software.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.