ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 160 - AZ-400 discussion

Report
Export

Your company is concerned that when developers introduce open source libraries, it creates licensing compliance issues.

You need to add an automated process to the build pipeline to detect when common open source libraries are added to the code base.

What should you use?

A.
Microsoft Visual SourceSafe
Answers
A.
Microsoft Visual SourceSafe
B.
Code Style
Answers
B.
Code Style
C.
Black Duck
Answers
C.
Black Duck
D.
Jenkins
Answers
D.
Jenkins
Suggested answer: C

Explanation:

Secure and Manage Open Source Software

Black Duck helps organizations identify and mitigate open source security, license compliance and code-quality risks across application and container portfolios. Black Duck Hub and its plugin for Team Foundation Server (TFS) allows you to automatically find and fix open source security vulnerabilities during the build process, so you can proactively manage risk. The integration allows you to receive alerts and fail builds when any Black Duck Hub policy violations are met.

Note:

There are several versions of this question in the exam. The question has two possible correct answers:

1. Black Duck

2. WhiteSource Bolt

Other incorrect answer options you may see on the exam include the following:

1. OWASP ZAP

2. PDM

3. SourceGear

Reference:

https://marketplace.visualstudio.com/items?itemName=black-duck-software.hub-tfs

asked 02/10/2024
Franziska Kreuz
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first