Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

A global software development company utilizes numerous open-source libraries and components in its commercial products. Due to recent supply chain attacks and increased scrutiny on software integrity, the cybersecurity architect needs to implement a technical strategy that automatically identifies vulnerabilities and license compliance issues within these open-source dependencies throughout the entire software development lifecycle (SDLC). The strategy must also provide actionable remediation guidance and integrate with existing CI/CD pipelines. Which strategy is MOST appropriate?

  1. ADeploying a Software Composition Analysis (SCA) solution.
  2. BEstablishing a manual code review process for all open-source components.
  3. CUtilizing a Dynamic Application Security Testing (DAST) tool for production applications.
  4. DImplementing a Static Application Security Testing (SAST) tool for proprietary code.
Show answer & explanation

Correct answer: A. Deploying a Software Composition Analysis (SCA) solution.

Software Composition Analysis (SCA) solutions are specifically designed to scan and identify open-source components within an application, detect known vulnerabilities in those components, and flag license compliance issues, integrating well into CI/CD pipelines.

Why the other options are wrong

  • B. A manual code review process for all open-source components is impractical, slow, and error-prone for a large number of dependencies and rapid development cycles.
  • C. DAST tests running applications for vulnerabilities from an outside perspective and does not focus on the composition or dependencies of open-source components within the code.
  • D. SAST analyzes proprietary source code for vulnerabilities but does not specifically address vulnerabilities or license issues in third-party open-source dependencies.

Software Composition Analysis (SCA)

SCA tools automate the identification of open-source components in a codebase, detect known vulnerabilities (CVEs) in those components, and flag license compliance issues.

  • Identifies open-source dependencies.
  • Detects vulnerabilities (CVEs) in third-party code.
  • Flags license compliance risks.
  • Integrates into CI/CD pipelines.

Memory trick: SCA is the 'Open-Source Inspector' checking for 'Component Risks'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions