CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security team wants to automatically identify known CVEs affecting third-party open-source libraries — including transitive dependencies — that are bundled inside their application's build artifacts. Which practice best addresses this requirement?
- ADynamic Application Security Testing (DAST)
- BFuzz testing
- CConfiguration compliance scanning
- DSoftware Composition Analysis (SCA)
Show answer & explanationAnswer & explanation
Correct answer: D. Software Composition Analysis (SCA)
Software Composition Analysis (SCA) inventories open-source and third-party components (often producing an SBOM) and cross-references them against vulnerability databases to identify known CVEs, including in transitive dependencies. DAST and fuzzing test application behavior, not dependency inventories.
Why the other options are wrong
- A. DAST tests the running application's behavior, not its embedded library inventory.
- B. Fuzzing injects malformed input to find crashes, unrelated to dependency tracking.
- C. Configuration compliance scanning checks system settings against a baseline, not code dependencies.
Software Composition Analysis (SCA)
SCA identifies and inventories third-party and open-source components within software, matching them against known vulnerability databases (often producing an SBOM).
- Detects vulnerable transitive dependencies
- Often generates a Software Bill of Materials (SBOM)
- Complements SAST/DAST for full application coverage
Memory trick: SCA checks the ingredients label for recalled parts