hardMultiple Select
CISSP Practice Question: Which THREE of the following are essential…
Which THREE of the following are essential components of a software supply chain security program? (Select exactly three.)
⚠ Common exam trap
ISC2 often tests the distinction between general security practices (like penetration testing or static analysis) and the specific, unique controls required for software supply chain security, such as artifact signing and vendor assessments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using signed and verified software artifacts
Option A is correct because using signed and verified software artifacts ensures integrity and authenticity through cryptographic signatures (e.g., GPG, Sigstore), preventing tampering or substitution of components within the supply chain. Option B is correct because maintaining a software bill of materials (SBOM) for all dependencies provides the inventory and transparency needed to identify and respond to vulnerabilities such as Log4Shell across transitive dependencies. Option E is correct because performing security assessments on third-party vendors addresses the risk introduced by external suppliers, a core element of supply chain risk management. Option C is not essential to a supply chain security program because penetration testing the production environment tests deployed infrastructure and applications rather than the provenance, integrity, or composition of software components. Option D is not essential because static analysis on in-house code improves code quality and finds coding flaws but does not address the third-party dependencies, artifact integrity, or vendor risks that define supply chain security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Using signed and verified software artifacts
Why this is correct
Signed and verified artefacts let consumers confirm software originated from a trusted publisher and was not tampered with in transit. This cryptographic provenance check directly satisfies the stem's requirement for an essential component of software supply chain security.
- ✓
Maintaining a software bill of materials (SBOM) for all dependencies
Why this is correct
An SBOM enumerates every component and dependency in the software, giving the visibility needed to identify and remediate vulnerable or compromised libraries when a new CVE emerges. Without this inventory, organisations cannot trace transitive dependencies, so it directly satisfies the supply chain security programme's requirement for component transparency.
- ✗
Running penetration tests on the production environment
Why it's wrong here
Penetration testing validates deployed systems, not the provenance, integrity or build pipeline of third-party components. It is tempting because penetration testing is a core security activity, and it would be correct when assessing exploitable vulnerabilities in a running application rather than securing the supply chain.
- ✗
Conducting static analysis on all in-house code
Why it's wrong here
Static analysis covers only in-house code, leaving third-party components, dependencies and build integrity unverified. It is tempting because static analysis is a genuine secure-development control, and it would be correct when the requirement is finding coding defects in source the organisation writes itself.
- ✓
Performing security assessments on third-party vendors
Why this is correct
Third-party vendors introduce inherited risk, so assessing their security controls before integration identifies weaknesses that could compromise the supply chain. This due-diligence step directly satisfies the stem's requirement for an essential component of a software supply chain security programme.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.