[Tools and Code Analysis]
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
Software Composition Analysis (SCA) is used to analyze dependencies in applications and identify vulnerable open-source libraries.
Option A (VM - Virtual Machine) : A VM is a computing environment, not a vulnerability detection tool.
Option B (IAST - Interactive Application Security Testing) : IAST analyzes runtime behavior, but it does not specialize in detecting vulnerable libraries.
Option C (DAST - Dynamic Application Security Testing) : DAST scans running applications for vulnerabilities, but it does not analyze open-source libraries.
Option D (SCA - Software Composition Analysis) : Correct.
Identifies security flaws in dependencies.
Used for managing supply chain risks.
Reference: CompTIA PenTest+ PT0-003 Official Guide -- Software Composition Analysis (SCA)
Glen
5 months agoJose
5 months agoGayla
5 months agoGeorgene
6 months agoAn
6 months agoGeraldo
6 months agoDana
6 months agoLeslee
7 months agoBettye
7 months agoNicolette
7 months agoTawny
7 months agoBette
7 months agoLaticia
8 months agoShoshana
8 months agoDelsie
8 months agoStephanie
8 months agoNancey
8 months agoPaola
8 months agoMalcolm
9 months agoArthur
9 months agoMatilda
9 months agoWai
9 months agoMindy
10 months agoShantell
10 months agoCora
10 months agoLinn
4 months agoKanisha
5 months agoNickolas
5 months agoReid
5 months agoRamonita
9 months ago