CSSLP · domain
Secure Software Supply Chain
Practise (ISC)2 Certified Secure Software Lifecycle Professional (CSSLP) (CSSLP) Secure Software Supply Chain practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Secure Software Supply Chain questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Secure Software Supply Chain
Secure Software Supply Chain questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Secure Software Supply Chain exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Secure Software Supply Chain questions (20)
Click any question to see the full explanation, or start a practice session above.
When designing an automated pipeline to prevent supply chain attacks, which THREE of the following features should be included in your artifact registry?
Medium2What is the primary function of a 'Vulnerability Disclosure Policy' (VDP) in a vendor's secure development lifecycle?
Easy3Your development team is integrating a new third-party library via npm. To prevent dependency confusion attacks where a malicious package is pulled from a public registry instead of your internal private registry, which configuration should be applied?
Medium4You notice that your build server environment pulls Docker images from a public registry with the ':latest' tag. Why is this a major supply chain security flaw?
Medium5To protect against a compromised build pipeline, which TWO of the following configurations should be implemented to ensure 'Hermetic Builds'?
Medium6When performing a vendor security assessment for a new SaaS product, which THREE of the following should be requested to evaluate their supply chain resilience?
Medium7An organization is adopting the SLSA (Supply-chain Levels for Software Artifacts) framework. To achieve Level 3, what requirement must be met regarding the build platform?
Hard8A supplier asks you to describe your 'Supply Chain Security Policy'. What is the most appropriate foundational element to include?
Easy9During a vendor security assessment, you require a supplier to provide proof that their software is signed. Which mechanism should you verify to ensure the code's integrity and origin authenticity?
Easy10You are setting up an automated policy in GitHub Actions to block builds that contain dependencies with known high-severity vulnerabilities. Which tool is standard for this type of automated gated check?
Medium11When evaluating a vendor's open-source usage, which factor is the strongest indicator of a proactive security posture?
Easy12Which THREE of the following are common threats to the Software Supply Chain that an SBOM can help mitigate?
Hard13Your organization uses a 'Golden Image' approach for build containers. To prevent supply chain contamination of these build environments, what is the most effective security control?
Medium14To defend against 'Dependency Confusion' attacks, which TWO of the following configurations should you apply to your private package manager?
Hard15You are auditing a third-party vendor's CI/CD pipeline integration. You notice they pull dependencies from public mirrors without pinning them to specific hashes. What is the primary security risk here?
Hard16You are using 'in-toto' to secure your software supply chain. What is the primary purpose of a 'layout' file in this framework?
Medium17An organization is concerned about 'Typosquatting' in their build system. Which strategy is most effective at preventing the accidental inclusion of malicious, similarly-named packages?
Hard18You are implementing a Software Bill of Materials (SBOM) using the CycloneDX standard for your CI/CD pipeline. Which of the following fields is mandatory to uniquely identify an individual component within the SBOM to ensure accurate vulnerability tracking?
Hard19Which TWO of the following are essential components of an effective Vendor Security Assessment program?
Easy20When assessing a SaaS provider's supply chain, you are concerned about their 'Vendor Risk Management' (VRM) program. Which practice indicates a mature approach to fourth-party risk?
HardOther domains
All CSSLP exam domains
Frequently asked questions
- What does the Secure Software Supply Chain domain cover on the CSSLP exam?
- Secure Software Supply Chain questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 20 Secure Software Supply Chain questions in the CSSLP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Secure Software Supply Chain questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.