CompTIA Cloud+ (CV0-004)SecurityHard

A software development company is adopting a DevOps model and requires a solution to scan container images for known vulnerabilities as part of their continuous integration/continuous deployment (CI/CD) pipeline. The solution must integrate seamlessly into the pipeline and prevent deployment of images with critical vulnerabilities. Which security practice is being implemented?

  1. AStatic Application Security Testing (SAST)
  2. BRuntime Application Self-Protection (RASP)
  3. CDynamic Application Security Testing (DAST)
  4. DSoftware Composition Analysis (SCA)
Show answer & explanation

Correct answer: D. Software Composition Analysis (SCA)

Software Composition Analysis (SCA) tools are specifically designed to identify known vulnerabilities in open-source components and third-party libraries used within applications and container images. Integrating SCA into a CI/CD pipeline allows for automated scanning and prevention of deployments with critical vulnerabilities inherited from these components.

Why the other options are wrong

  • A. SAST analyzes source code for vulnerabilities before compilation, but doesn't specifically target third-party library vulnerabilities in compiled container images.
  • B. RASP protects applications from attacks during runtime, not pre-deployment vulnerability scanning of container images.
  • C. DAST tests applications in a running state by simulating attacks, not for static vulnerability scanning of container images in a CI/CD pipeline.

Software Composition Analysis (SCA)

SCA tools analyze an application's codebase to identify all open-source and third-party components, detect known vulnerabilities (CVEs), and assess licensing risks associated with them.

  • Focuses on third-party and open-source components.
  • Identifies known vulnerabilities (CVEs).
  • Integrates into CI/CD pipelines.
  • Crucial for container security and supply chain risk management.
  • Often includes license compliance checks.

Memory trick: SCA 'S'cans 'C'ontainers for 'A'll known vulnerabilities in their parts.

More Security questions