CompTIA Cloud+ (CV0-004)SecurityHard
A software development company is adopting a DevOps model and requires a solution to scan container images for known vulnerabilities as part of their continuous integration/continuous deployment (CI/CD) pipeline. The solution must integrate seamlessly into the pipeline and prevent deployment of images with critical vulnerabilities. Which security practice is being implemented?
- AStatic Application Security Testing (SAST)
- BRuntime Application Self-Protection (RASP)
- CDynamic Application Security Testing (DAST)
- DSoftware Composition Analysis (SCA)
Show answer & explanationAnswer & explanation
Correct answer: D. Software Composition Analysis (SCA)
Software Composition Analysis (SCA) tools are specifically designed to identify known vulnerabilities in open-source components and third-party libraries used within applications and container images. Integrating SCA into a CI/CD pipeline allows for automated scanning and prevention of deployments with critical vulnerabilities inherited from these components.
Why the other options are wrong
- A. SAST analyzes source code for vulnerabilities before compilation, but doesn't specifically target third-party library vulnerabilities in compiled container images.
- B. RASP protects applications from attacks during runtime, not pre-deployment vulnerability scanning of container images.
- C. DAST tests applications in a running state by simulating attacks, not for static vulnerability scanning of container images in a CI/CD pipeline.
Software Composition Analysis (SCA)
SCA tools analyze an application's codebase to identify all open-source and third-party components, detect known vulnerabilities (CVEs), and assess licensing risks associated with them.
- Focuses on third-party and open-source components.
- Identifies known vulnerabilities (CVEs).
- Integrates into CI/CD pipelines.
- Crucial for container security and supply chain risk management.
- Often includes license compliance checks.
Memory trick: SCA 'S'cans 'C'ontainers for 'A'll known vulnerabilities in their parts.