
Certified Secure Software Lifecycle Professional
Domain 8Objective 3
Verify Pedigree and Provenance CSSLP Practice Questions (Page 4)
Part of the Secure Software Supply Chain domain, which accounts for 10% of the CSSLP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 28 practice questions to prepare you well beyond it. (estimate)
28questions here
6free pages
9concepts
10%of the exam
Questions 16–20
- 16
Which algorithm is commonly used to compute a cryptographic hash for verifying software integrity?
Select an answer first - 17
Why is isolation important for a build environment?
Select an answer first - 18
Which protocol is designed to provide authenticated and encrypted file transfers over a secure channel?
Select an answer first - 19
Why is the right to audit important for supply chain security?
Select an answer first - 20
A security engineer downloads a software artifact from a vendor's website. The vendor provides a SHA-256 checksum. The engineer computes the checksum of the downloaded file and it matches. However, the engineer is still concerned about the authenticity of the file. Why might the checksum match be insufficient?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CSSLP” is a trademark of its owner, used for identification only.