Web › Module 3 › Lesson 5
Quiz — Supply Chain Failures
10 APPLY on A03: deps, SBOM/pins, inventory, demo http://192.168.0.1/ ethics.
Opening
Software Supply Chain Failures — Module Quiz
Ten APPLY items on OWASP Top 10:2025 A03: dependencies as attack surface, direct vs transitive, SBOM and pinning, trust boundaries, compromise story beats without malware samples, inventory labs on projects you own, $HOME/cyberlium-lab notes chmod 600.
Knowledge Check
APPLY: Why are dependencies A03 attack surface?
Multiple choice
Knowledge Check
APPLY: True or False: Transitive dependencies cannot introduce supply-chain risk.
True or False
Knowledge Check
APPLY: What does an SBOM help you do after a CVE drops?
Multiple choice
Knowledge Check
APPLY: Pinning vs floating latest — which reduces surprise malicious publishes between builds?
Multiple choice
Knowledge Check
APPLY: True or False: Publishing a typosquat package is acceptable Cyberlium homework to “feel A03.”
True or False
Knowledge Check
APPLY: A trusted package version looks malicious. First defender moves?
Multiple choice
Knowledge Check
APPLY: Name a trust boundary in the supply chain.
Multiple choice
Knowledge Check
APPLY: curl http://192.168.0.1/ shows a TP-Link/Netgear “Router Admin” login. What do you do?
Multiple choice
Knowledge Check
APPLY: True or False: Pasting employer registry tokens into public notes proves you did the lab.
True or False
Knowledge Check
APPLY: You finish A03. What opens next?
Multiple choice
Answer all 10 knowledge checks to continue. (0/10 answered)