Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A global software development company utilizes numerous open-source libraries and components in its commercial products. Due to recent supply chain attacks and increased scrutiny on software integrity, the cybersecurity architect needs to implement a technical strategy that automatically identifies vulnerabilities and license compliance issues within these open-source dependencies throughout the entire software development lifecycle (SDLC). The strategy must also provide actionable remediation guidance and integrate with existing CI/CD pipelines. Which strategy is MOST appropriate?
- ADeploying a Software Composition Analysis (SCA) solution.
- BEstablishing a manual code review process for all open-source components.
- CUtilizing a Dynamic Application Security Testing (DAST) tool for production applications.
- DImplementing a Static Application Security Testing (SAST) tool for proprietary code.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploying a Software Composition Analysis (SCA) solution.
Software Composition Analysis (SCA) solutions are specifically designed to scan and identify open-source components within an application, detect known vulnerabilities in those components, and flag license compliance issues, integrating well into CI/CD pipelines.
Why the other options are wrong
- B. A manual code review process for all open-source components is impractical, slow, and error-prone for a large number of dependencies and rapid development cycles.
- C. DAST tests running applications for vulnerabilities from an outside perspective and does not focus on the composition or dependencies of open-source components within the code.
- D. SAST analyzes proprietary source code for vulnerabilities but does not specifically address vulnerabilities or license issues in third-party open-source dependencies.
Software Composition Analysis (SCA)
SCA tools automate the identification of open-source components in a codebase, detect known vulnerabilities (CVEs) in those components, and flag license compliance issues.
- Identifies open-source dependencies.
- Detects vulnerabilities (CVEs) in third-party code.
- Flags license compliance risks.
- Integrates into CI/CD pipelines.
Memory trick: SCA is the 'Open-Source Inspector' checking for 'Component Risks'.