CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security team is performing a vulnerability assessment on a newly deployed containerized application. The assessment needs to include scanning the container images for known vulnerabilities in their operating system libraries and third-party dependencies before deployment. Which security analysis technique is most appropriate for identifying these types of vulnerabilities within the container images?
- ADynamic Application Security Testing (DAST)
- BStatic Application Security Testing (SAST)
- CSoftware Composition Analysis (SCA)
- DInteractive Application Security Testing (IAST)
Show answer & explanationAnswer & explanation
Correct answer: C. Software Composition Analysis (SCA)
Software Composition Analysis (SCA) specifically focuses on identifying vulnerabilities in open-source and third-party components (dependencies, libraries) used within an application, which is critical for container images.
Why the other options are wrong
- A. DAST tests applications in a running state by simulating attacks, primarily for runtime vulnerabilities, not static image components.
- B. SAST analyzes source code or compiled code for security flaws without executing the application, but it focuses on proprietary code logic, not typically third-party component vulnerabilities.
- D. IAST combines elements of SAST and DAST, analyzing applications from within during runtime, which is not ideal for pre-deployment image scanning for dependencies.
Software Composition Analysis (SCA)
A security analysis technique that identifies open-source and third-party components within an application and scans them for known vulnerabilities, license compliance issues, and outdated versions.
- Crucial for container security due to extensive use of base images and libraries.
- Helps manage supply chain risks.
- Typically integrated into CI/CD pipelines.
Memory trick: DAST, SAST, SCA, IAST: Don't Stop Scanning All Infrastructure And Software Thoroughly.