Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard
A global software development company utilizes numerous open-source libraries and components in its commercial products. To comply with software supply chain security regulations (e.g., NIST SSDF) and manage associated risks, the cybersecurity architect needs a strategy to continuously identify and mitigate vulnerabilities in these components. Which technical strategy is most effective?
- AImplementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.
- BRestricting the use of all open-source software to only components listed on an approved internal whitelist.
- CManually reviewing the license agreements of all open-source components during product release.
- DPerforming annual penetration tests on the final product to detect supply chain vulnerabilities.
Show answer & explanationAnswer & explanation
Correct answer: A. Implementing a Software Composition Analysis (SCA) tool integrated into the CI/CD pipeline and artifact repositories to continuously scan for known vulnerabilities and license compliance issues.
An SCA tool integrated into the CI/CD pipeline provides continuous, automated scanning for known vulnerabilities and license compliance issues in open-source components, directly addressing software supply chain security risks and regulatory requirements.
Why the other options are wrong
- B. Restricting open-source use can limit innovation and still requires a mechanism to ensure the whitelisted components are secure and up-to-date; it's a policy, not a comprehensive technical solution for continuous vulnerability management.
- C. Manual license review is insufficient for identifying security vulnerabilities and is not scalable or continuous, failing to meet supply chain security requirements.
- D. Annual penetration tests are too late and infrequent to effectively manage the dynamic risk of open-source component vulnerabilities in a fast-paced development environment.
Software Composition Analysis (SCA)
SCA tools analyze software applications to identify and inventory open-source and third-party components, scanning them for known security vulnerabilities and license compliance issues.
- Essential for managing software supply chain risks.
- Integrates into CI/CD pipelines for continuous monitoring.
- Helps ensure compliance with licensing and security policies.
Memory trick: SCA Scans the Supply Chain Continuously