
Certified Secure Software Lifecycle Professional
Domain 8Objective 1
Implement Software Supply Chain Risk Management (e.g., International Organization for Standardization (ISO), National Institute of Standards and Technology (NIST)) CSSLP Practice Questions (Page 2)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 20 practice questions to prepare you well beyond it. (estimate)
20questions here
4free pages
4concepts
10%of the exam
Questions 6–10
- 6
A company has multiple products that share several third-party components. They want to ensure that when a vulnerability is disclosed, they can quickly identify all affected products. What should they implement?
Select an answer first - 7
A security team receives an alert about a critical vulnerability in a component that is listed in their SBOM. The component is used in a production application. What should the team do first?
Select an answer first - 8
During component risk assessment, a team discovers that a third-party library has a known vulnerability but no patch is available. What is the most appropriate next step?
Select an answer first - 9
A security team subscribes to vulnerability alerts for the third-party libraries used in their product. What is the primary purpose of this continuous monitoring activity?
Select an answer first - 10
A security architect is establishing a policy for approving open-source components. Which practice best supports secure component identification and selection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.