CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium

A security team wants to automatically identify known CVEs affecting third-party open-source libraries — including transitive dependencies — that are bundled inside their application's build artifacts. Which practice best addresses this requirement?

  1. ADynamic Application Security Testing (DAST)
  2. BFuzz testing
  3. CConfiguration compliance scanning
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: D. Software Composition Analysis (SCA)

Software Composition Analysis (SCA) inventories open-source and third-party components (often producing an SBOM) and cross-references them against vulnerability databases to identify known CVEs, including in transitive dependencies. DAST and fuzzing test application behavior, not dependency inventories.

Why the other options are wrong

  • A. DAST tests the running application's behavior, not its embedded library inventory.
  • B. Fuzzing injects malformed input to find crashes, unrelated to dependency tracking.
  • C. Configuration compliance scanning checks system settings against a baseline, not code dependencies.

Software Composition Analysis (SCA)

SCA identifies and inventories third-party and open-source components within software, matching them against known vulnerability databases (often producing an SBOM).

  • Detects vulnerable transitive dependencies
  • Often generates a Software Bill of Materials (SBOM)
  • Complements SAST/DAST for full application coverage

Memory trick: SCA checks the ingredients label for recalled parts

More Vulnerability Management questions