[Tools and Code Analysis]
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
Software Composition Analysis (SCA) is used to analyze dependencies in applications and identify vulnerable open-source libraries.
Option A (VM - Virtual Machine) : A VM is a computing environment, not a vulnerability detection tool.
Option B (IAST - Interactive Application Security Testing) : IAST analyzes runtime behavior, but it does not specialize in detecting vulnerable libraries.
Option C (DAST - Dynamic Application Security Testing) : DAST scans running applications for vulnerabilities, but it does not analyze open-source libraries.
Option D (SCA - Software Composition Analysis) : Correct.
Identifies security flaws in dependencies.
Used for managing supply chain risks.
Reference: CompTIA PenTest+ PT0-003 Official Guide -- Software Composition Analysis (SCA)
Glen
1 month agoJose
2 months agoGayla
2 months agoGeorgene
2 months agoAn
2 months agoGeraldo
2 months agoDana
2 months agoLeslee
3 months agoBettye
3 months agoNicolette
3 months agoTawny
4 months agoBette
4 months agoLaticia
4 months agoShoshana
4 months agoDelsie
4 months agoStephanie
4 months agoNancey
5 months agoPaola
5 months agoMalcolm
5 months agoArthur
5 months agoMatilda
5 months agoWai
6 months agoMindy
6 months agoShantell
6 months agoCora
6 months agoLinn
21 days agoKanisha
26 days agoNickolas
1 month agoReid
1 month agoRamonita
5 months ago