Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CSA CCSK Exam - Topic 6 Question 103 Discussion

How can the use of third-party libraries introduce supply chain risks in software development?
B) They might contain vulnerabilities that can be exploited
A) They are usually open source and do not require vetting
C) They fail to integrate properly with existing continuous integration pipelines
D) They might increase the overall complexity of the codebase

CSA CCSK Exam - Topic 6 Question 103 Discussion

Actual exam question for CSA's CCSK exam
Question #: 103
Topic #: 6
[All CCSK Questions]

How can the use of third-party libraries introduce supply chain risks in software development?

Show Suggested Answer Hide Answer
Suggested Answer: B

The use of third-party libraries in software development can introduce supply chain risks because these libraries might contain vulnerabilities that can be exploited. Since third-party libraries often come from external sources, they might not be thoroughly vetted or maintained with the same level of scrutiny as in-house code. Vulnerabilities in these libraries can lead to security breaches, data leaks, or other forms of exploitation if not properly managed and updated.

Although many third-party libraries are open-source, they still require proper vetting for security and compatibility. Integration issues, while a concern, are not directly related to the supply chain risks posed by vulnerabilities. While increased complexity is a challenge, it does not directly relate to security risks or supply chain concerns.


Contribute your Thoughts:

0/2000 characters
Complexity definitely seems like a valid concern, but I wonder if it's as significant as the potential vulnerabilities in option B.
upvoted 0 times
...
Beatriz
5 days ago
I feel like I've seen a practice question about integration issues with CI pipelines before, but I'm not sure if that's the main risk here.
upvoted 0 times
...
Kent
10 days ago
I think option A might be misleading; not all open-source libraries are unvetted, but they can still pose risks.
upvoted 0 times
...
Phil
15 days ago
I remember discussing how third-party libraries can introduce vulnerabilities, especially if they aren't regularly updated.
upvoted 0 times
...

Save Cancel