Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

APICS CPIM-8.0 Exam - Topic 2 Question 20 Discussion

During a manual source code review, an organization discovered a dependency with an open-source library that has a history of being exploited. Which action should the organization take FIRST to assess the risk of depending on the open-source library?
A) Identify the specific version of the open-source library that is implemented
B) Request a penetration test that will attempt to exploit the open-source library
C) Deploy the latest compatible version of the open-source library
D) Submit a change request to remove software dependencies with the open-source library

APICS CPIM-8.0 Exam - Topic 2 Question 20 Discussion

Actual exam question for APICS's CPIM-8.0 exam
Question #: 20
Topic #: 2
[All CPIM-8.0 Questions]

During a manual source code review, an organization discovered a dependency with an open-source library that has a history of being exploited. Which action should the organization take FIRST to assess the risk of depending on the open-source library?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Annice
3 days ago
Agreed! If we know the version, we can check for known exploits.
upvoted 0 times
...
Cyndy
8 days ago
I think A is the best choice. Knowing the version helps assess vulnerabilities.
upvoted 0 times
...
Clorinda
14 days ago
C could work, but we need to confirm the current version first.
upvoted 0 times
...
Myong
19 days ago
B seems risky. We should know what we're dealing with first.
upvoted 0 times
...
Mari
24 days ago
Agreed, A helps assess the specific vulnerabilities.
upvoted 0 times
...
Alex
29 days ago
I think A is the best choice. Knowing the version is crucial.
upvoted 0 times
...
Tayna
1 month ago
I feel like option D is too drastic. We should assess before removing anything.
upvoted 0 times
...
Joaquin
1 month ago
Option C sounds tempting, but we need to know what we're dealing with first.
upvoted 0 times
...
Avery
1 month ago
Agreed! Without the version, we can't determine if it's safe or not.
upvoted 0 times
...
Lawrence
2 months ago
I think option A is the best first step. Knowing the version helps assess vulnerabilities.
upvoted 0 times
...
Wynell
2 months ago
Really? I thought we should just test it first. B) sounds like a good idea too.
upvoted 0 times
...
Tatum
2 months ago
C) is risky, you could introduce new vulnerabilities!
upvoted 0 times
...
Walker
4 months ago
Wait, why not just remove it right away? D) seems safer.
upvoted 0 times
...
Mitsue
4 months ago
Totally agree, can't assess risk without knowing the version!
upvoted 0 times
...
Kristofer
4 months ago
A) is the best first step, gotta know what version you're dealing with.
upvoted 0 times
...
Kindra
4 months ago
Removing dependencies might be too drastic without assessing first.
upvoted 0 times
...
Shalon
4 months ago
Updating to the latest version is usually a good move.
upvoted 0 times
...
Gilberto
4 months ago
Surprised they even used that library in the first place!
upvoted 0 times
...
Stefanie
5 months ago
I think a penetration test is overkill at this stage.
upvoted 0 times
...
Ardella
5 months ago
Gotta check the specific version first!
upvoted 0 times
...
Lashon
5 months ago
I wonder if deploying the latest version is really the best first step. I think we need to understand the risks of the current version before doing anything drastic.
upvoted 0 times
...
Thad
5 months ago
I practiced a similar question, and I feel like jumping straight to a penetration test might be premature. We should know what version we're dealing with first.
upvoted 0 times
...
Vesta
5 months ago
I'm not entirely sure, but I remember something about needing to assess the current version before making any changes. It seems like option A makes sense.
upvoted 0 times
...
Alisha
5 months ago
I think the first step should be to identify the specific version of the open-source library. That way, we can see if it has known vulnerabilities.
upvoted 0 times
...

Save Cancel