Courseiva
hardMultiple Select

CISSP Practice Question: Which THREE of the following are essential…

Which THREE of the following are essential components of a software supply chain security program? (Select exactly three.)

⚠ Common exam trap

ISC2 often tests the distinction between general security practices (like penetration testing or static analysis) and the specific, unique controls required for software supply chain security, such as artifact signing and vendor assessments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using signed and verified software artifacts

Option A is correct because using signed and verified software artifacts ensures integrity and authenticity through cryptographic signatures (e.g., GPG, Sigstore), preventing tampering or substitution of components within the supply chain. Option B is correct because maintaining a software bill of materials (SBOM) for all dependencies provides the inventory and transparency needed to identify and respond to vulnerabilities such as Log4Shell across transitive dependencies. Option E is correct because performing security assessments on third-party vendors addresses the risk introduced by external suppliers, a core element of supply chain risk management. Option C is not essential to a supply chain security program because penetration testing the production environment tests deployed infrastructure and applications rather than the provenance, integrity, or composition of software components. Option D is not essential because static analysis on in-house code improves code quality and finds coding flaws but does not address the third-party dependencies, artifact integrity, or vendor risks that define supply chain security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Using signed and verified software artifacts

    Why this is correct

    Signed and verified artefacts let consumers confirm software originated from a trusted publisher and was not tampered with in transit. This cryptographic provenance check directly satisfies the stem's requirement for an essential component of software supply chain security.

  • ✓

    Maintaining a software bill of materials (SBOM) for all dependencies

    Why this is correct

    An SBOM enumerates every component and dependency in the software, giving the visibility needed to identify and remediate vulnerable or compromised libraries when a new CVE emerges. Without this inventory, organisations cannot trace transitive dependencies, so it directly satisfies the supply chain security programme's requirement for component transparency.

  • ✗

    Running penetration tests on the production environment

    Why it's wrong here

    Penetration testing validates deployed systems, not the provenance, integrity or build pipeline of third-party components. It is tempting because penetration testing is a core security activity, and it would be correct when assessing exploitable vulnerabilities in a running application rather than securing the supply chain.

  • ✗

    Conducting static analysis on all in-house code

    Why it's wrong here

    Static analysis covers only in-house code, leaving third-party components, dependencies and build integrity unverified. It is tempting because static analysis is a genuine secure-development control, and it would be correct when the requirement is finding coding defects in source the organisation writes itself.

  • ✓

    Performing security assessments on third-party vendors

    Why this is correct

    Third-party vendors introduce inherited risk, so assessing their security controls before integration identifies weaknesses that could compromise the supply chain. This due-diligence step directly satisfies the stem's requirement for an essential component of a software supply chain security programme.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.