CompTIA Cloud+ (CV0-004)SecurityHard

A cloud security team is performing a vulnerability assessment on a newly deployed containerized application. The assessment needs to include scanning the container images for known vulnerabilities in their operating system libraries and third-party dependencies before deployment. Which security analysis technique is most appropriate for identifying these types of vulnerabilities within the container images?

  1. ADynamic Application Security Testing (DAST)
  2. BStatic Application Security Testing (SAST)
  3. CSoftware Composition Analysis (SCA)
  4. DInteractive Application Security Testing (IAST)
Show answer & explanation

Correct answer: C. Software Composition Analysis (SCA)

Software Composition Analysis (SCA) specifically focuses on identifying vulnerabilities in open-source and third-party components (dependencies, libraries) used within an application, which is critical for container images.

Why the other options are wrong

  • A. DAST tests applications in a running state by simulating attacks, primarily for runtime vulnerabilities, not static image components.
  • B. SAST analyzes source code or compiled code for security flaws without executing the application, but it focuses on proprietary code logic, not typically third-party component vulnerabilities.
  • D. IAST combines elements of SAST and DAST, analyzing applications from within during runtime, which is not ideal for pre-deployment image scanning for dependencies.

Software Composition Analysis (SCA)

A security analysis technique that identifies open-source and third-party components within an application and scans them for known vulnerabilities, license compliance issues, and outdated versions.

  • Crucial for container security due to extensive use of base images and libraries.
  • Helps manage supply chain risks.
  • Typically integrated into CI/CD pipelines.

Memory trick: DAST, SAST, SCA, IAST: Don't Stop Scanning All Infrastructure And Software Thoroughly.

More Security questions