
Certified Secure Software Lifecycle Professional
Domain 8Objective 3
Verify Pedigree and Provenance CSSLP Practice Questions (Page 2)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
9concepts
10%of the exam
Questions 6–10
- 6
Which security measure is specifically designed to prevent unauthorized changes to a protected branch in a code repository?
Select an answer first - 7
A software vendor distributes a signed binary and a detached signature file. A consumer wants to verify that the binary was indeed produced by the vendor and has not been altered. Which process is correct?
Select an answer first - 8
A DevOps team needs to transfer a signed software artifact from an internal build server to a production repository hosted in a different cloud region. The artifact is large, and the team wants to ensure confidentiality and integrity during transit. Which approach best meets these requirements?
Select an answer first - 9
A company's build system automatically fetches open-source libraries from a public package repository. The security team wants to reduce the risk of a malicious package being introduced into the build. Which control is most effective?
Select an answer first - 10
Which practice is essential when interconnecting your software supply chain systems with external partners?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.