
Certified Secure Software Lifecycle Professional
Domain 8Objective 3
Verify Pedigree and Provenance CSSLP Practice Questions (Page 1)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
9concepts
10%of the exam
Questions 1–5
- 1
What is a trust boundary in the context of system interconnections?
Select an answer first - 2
What property of a cryptographic hash makes it useful for detecting tampering?
Select an answer first - 3
What is the primary purpose of maintaining a chain of custody for software components in a supply chain?
Select an answer first - 4
A company sources a critical software component from a third-party supplier. The supplier's development and build environments are not directly observable by the company. The company wants to verify the supplier's security practices and ensure the component's pedigree. Which action is most appropriate?
Select an answer first - 5
What does a digital signature provide for a software component?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.