Cyberlium

Web › Module 3 › Lesson 5

BeginnerModule 3Lesson 5/5

Quiz — Supply Chain Failures

10 APPLY on A03: deps, SBOM/pins, inventory, demo http://192.168.0.1/ ethics.

10 min+40 XP10 quiz
Module progress5 of 5

Opening

Software Supply Chain Failures — Module Quiz

Ten APPLY items on OWASP Top 10:2025 A03: dependencies as attack surface, direct vs transitive, SBOM and pinning, trust boundaries, compromise story beats without malware samples, inventory labs on projects you own, $HOME/cyberlium-lab notes chmod 600.

Knowledge Check

1

APPLY: Why are dependencies A03 attack surface?

Multiple choice

Knowledge Check

2

APPLY: True or False: Transitive dependencies cannot introduce supply-chain risk.

True or False

Knowledge Check

3

APPLY: What does an SBOM help you do after a CVE drops?

Multiple choice

Knowledge Check

4

APPLY: Pinning vs floating latest — which reduces surprise malicious publishes between builds?

Multiple choice

Knowledge Check

5

APPLY: True or False: Publishing a typosquat package is acceptable Cyberlium homework to “feel A03.”

True or False

Knowledge Check

6

APPLY: A trusted package version looks malicious. First defender moves?

Multiple choice

Knowledge Check

7

APPLY: Name a trust boundary in the supply chain.

Multiple choice

Knowledge Check

8

APPLY: curl http://192.168.0.1/ shows a TP-Link/Netgear “Router Admin” login. What do you do?

Multiple choice

Knowledge Check

9

APPLY: True or False: Pasting employer registry tokens into public notes proves you did the lab.

True or False

Knowledge Check

10

APPLY: You finish A03. What opens next?

Multiple choice

← Previous

Answer all 10 knowledge checks to continue. (0/10 answered)