A security architect is designing a vulnerability assessment strategy for a new cloud-native application developed using microservices. The application heavily relies on third-party APIs and open-source libraries. Which type of vulnerability assessment is LEAST effective for identifying vulnerabilities introduced by these external dependencies?
- AManual Code Review
- BDynamic Application Security Testing (DAST)
- CSoftware Composition Analysis (SCA)
- DStatic Application Security Testing (SAST)
Show answer & explanationAnswer & explanation
Correct answer: B. Dynamic Application Security Testing (DAST)
Software Composition Analysis (SCA) specifically focuses on identifying vulnerabilities in open-source and third-party components. Static Application Security Testing (SAST) and Manual Code Review can find issues within the *application's own code* that might misuse or interact poorly with libraries, but they don't inherently scan the *libraries themselves* for known vulnerabilities. Dynamic Application Security Testing (DAST) tests the running application from the outside, primarily looking for vulnerabilities in the application's exposed interfaces and runtime behavior, not typically scanning the internal components or their versions for known CVEs directly within the dependencies.
Why the other options are wrong
- A. Manual Code Review can be effective, especially if focused on how third-party libraries are integrated, but it's labor-intensive and doesn't automatically detect known CVEs in the libraries themselves.
- C. SCA is highly effective for identifying vulnerabilities in third-party and open-source components, making it a strong choice.
- D. SAST analyzes source code and can identify misconfigurations or misuse of libraries, but it doesn't primarily scan the libraries themselves for known CVEs.
Software Composition Analysis (SCA)
An automated process that identifies open-source and third-party components within an application and scans them for known security vulnerabilities and licensing issues.
- Crucial for applications using many external libraries.
- Helps manage supply chain risks.
- Often integrated into CI/CD pipelines.
Memory trick: SAST is code, DAST is live, SCA is ingredients, Manual is human eyes.