Secure CI/CD Knowledge Check
Table of Contents
Return to the Secure CI/CD Course
Answer all ten questions before opening the separate answer key . Write one sentence explaining each choice. Score at least eight on a closed-book attempt and correct every miss before the capstone. Retake the full quiz after review if your first score is lower. This is a skills check, not certification prep.
Questions
- Dependency change: A manifest changes one direct package, while the lockfile adds six packages. What else should you review? A. Only the direct package. B. The six transitive additions. C. Only the application source. D. No further input.
- Empty review view: GitHub shows no dependency diff. What is the best next step? A. Approve. B. Disable the dependency graph. C. Check feature availability and inspect the manifest and lockfile. D. Delete the lockfile.
- SBOM scope: Syft scans a source directory. What does the resulting SBOM establish? A. Every runtime component. B. Components the scanner found in that source target. C. Publisher identity. D. No vulnerabilities.
- Pull request token: A test job only needs checkout and tests. Which permission fits? A.
contents: read. B.contents: write. C.administration: write. D. All permissions. - Workflow boundary: Why keep untrusted pull request code out of a privileged release job? A. It improves formatting. B. The code may act with release authority. C. It reduces log size. D. It speeds the build.
- Scorecard: A check returns
?. What should you record? A. Zero risk. B. A pass. C. Unavailable evidence and a manual review need. D. A release approval. - Digest: A received file matches a digest copied from the same compromised server. What remains unproven? A. Byte equality with that digest. B. File size. C. Independent publisher trust. D. Hash algorithm name.
- Attestation: A valid attestation names a different repository than policy allows. What is the decision? A. Approve. B. Reject or hold. C. Ignore the repository. D. Rewrite the attestation.
- SLSA: Does an attestation alone prove a build meets a SLSA level? A. Yes. B. Only for private repositories. C. Only if the SBOM exists. D. No, review all level requirements.
- Lab: The tampered file produces a digest mismatch. What should the gate do? A. Publish with a note. B. Recompute the trusted digest from the tampered file. C. Reject and retain evidence. D. Ignore the exit code.
Review and Continue
After answering, open the answer key . For every missed question, link the relevant lesson section in your packet and rewrite the rule in your own words. Reanswer without looking at the key. Use the SLSA build track and GitHub’s secure use reference for questions 5 and 9.
Next: Complete the release gate capstone .


