Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A global software development company utilizes numerous open-source libraries and components in its commercial products. To comply with software supply chain security regulations (e.g., NIST SSDF) and manage associated risks, the cybersecurity architect needs a strategy to continuously identify and mitigate vulnerabilities in these components. Which technical strategy is most effective?

  1. AImplementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.
  2. BRestricting the use of all open-source software to only components listed on an approved internal whitelist.
  3. CManually reviewing the license agreements of all open-source components during product release.
  4. DPerforming annual penetration tests on the final product to detect supply chain vulnerabilities.
Show answer & explanation

Correct answer: A. Implementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.

An SCA tool integrated into the CI/CD pipeline provides continuous, automated scanning for known vulnerabilities and license compliance issues in open-source components, directly addressing software supply chain security risks and regulatory requirements.

Why the other options are wrong

  • B. Restricting open-source use can limit innovation and still requires a mechanism to ensure the whitelisted components are secure and up-to-date; it's a policy, not a comprehensive technical solution for continuous vulnerability management.
  • C. Manual license review is insufficient for identifying security vulnerabilities and is not scalable or continuous, failing to meet supply chain security requirements.
  • D. Annual penetration tests are too late and infrequent to effectively manage the dynamic risk of open-source component vulnerabilities in a fast-paced development environment.

Software Composition Analysis (SCA)

SCA tools analyze software applications to identify and inventory open-source and third-party components, scanning them for known security vulnerabilities and license compliance issues.

  • Essential for managing software supply chain risks.
  • Integrates into CI/CD pipelines for continuous monitoring.
  • Helps ensure compliance with licensing and security policies.

Memory trick: SCA Scans the Supply Chain Continuously

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions