ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 383 - CAS-004 discussion

Report
Export

A senior security analyst is helping the development team improve the security of an application that is being developed. The developers use third-party libraries and applications. The software in development used old, third-party packages that were not replaced before market distribution. Which of the following should be implemented into the SDLC to resolve the issue?

A.
Software composition analysis
Answers
A.
Software composition analysis
B.
A SCAP scanner
Answers
B.
A SCAP scanner
C.
ASAST
Answers
C.
ASAST
D.
A DAST
Answers
D.
A DAST
Suggested answer: A

Explanation:

Software Composition Analysis (SCA) is a process that identifies the open-source components used in software development to manage the risks associated with third-party components. Implementing SCA into the Software Development Life Cycle (SDLC) can help identify outdated third-party packages and ensure they are replaced or updated before the software is distributed.

asked 02/10/2024
yusuf sivrikaya
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first