ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 509 - CAS-004 discussion

Report
Export

A software development company needs to mitigate third-party risks to its software supply chain. Which of the following techniques should the company use in the development environment to best meet this objective?

A.
Performing software composition analysis
Answers
A.
Performing software composition analysis
B.
Requiring multifactor authentication
Answers
B.
Requiring multifactor authentication
C.
Establishing coding standards and monitoring for compliance
Answers
C.
Establishing coding standards and monitoring for compliance
D.
Implementing a robust unit and regression-testing scheme
Answers
D.
Implementing a robust unit and regression-testing scheme
Suggested answer: A

Explanation:

Software composition analysis (SCA) is the most effective method to mitigate third-party risks in a software supply chain. SCA tools analyze the open-source and third-party components used in software development to identify known vulnerabilities, outdated dependencies, or licensing issues. By integrating SCA into the development environment, the company can proactively address risks related to external libraries or codebases that may introduce vulnerabilities into the software supply chain. CASP+ emphasizes the importance of securing the supply chain, particularly by identifying and addressing risks introduced by third-party software components.

CASP+ CAS-004 Exam Objectives: Domain 3.0 -- Enterprise Security Architecture (Third-Party Risk Management)

CompTIA CASP+ Study Guide: Securing Software Supply Chains with SCA

asked 02/10/2024
selvaram vijayaragavan
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first