[Tools and Code Analysis]
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
Software Composition Analysis (SCA) is used to analyze dependencies in applications and identify vulnerable open-source libraries.
Option A (VM - Virtual Machine) : A VM is a computing environment, not a vulnerability detection tool.
Option B (IAST - Interactive Application Security Testing) : IAST analyzes runtime behavior, but it does not specialize in detecting vulnerable libraries.
Option C (DAST - Dynamic Application Security Testing) : DAST scans running applications for vulnerabilities, but it does not analyze open-source libraries.
Option D (SCA - Software Composition Analysis) : Correct.
Identifies security flaws in dependencies.
Used for managing supply chain risks.
Reference: CompTIA PenTest+ PT0-003 Official Guide -- Software Composition Analysis (SCA)
Glen
3 months agoJose
3 months agoGayla
3 months agoGeorgene
3 months agoAn
4 months agoGeraldo
4 months agoDana
4 months agoLeslee
5 months agoBettye
5 months agoNicolette
5 months agoTawny
5 months agoBette
5 months agoLaticia
5 months agoShoshana
6 months agoDelsie
6 months agoStephanie
6 months agoNancey
6 months agoPaola
6 months agoMalcolm
6 months agoArthur
7 months agoMatilda
7 months agoWai
7 months agoMindy
7 months agoShantell
8 months agoCora
8 months agoLinn
2 months agoKanisha
2 months agoNickolas
3 months agoReid
3 months agoRamonita
7 months ago