Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Linux Foundation CNPA Exam - Topic 3 Question 2 Discussion

Actual exam question for Linux Foundation's CNPA exam
Question #: 2
Topic #: 3
[All CNPA Questions]

In the context of platform engineering and the effective delivery of platform software, which of the following statements describes the role of CI/CD pipelines in relation to Software Bill of Materials (SBOM) and security scanning?

Show Suggested Answer Hide Answer
Suggested Answer: B

Modern platform engineering requires security and compliance to be integral parts of the delivery process, not afterthoughts. CI/CD pipelines are the foundation for delivering platform software rapidly and reliably, and integrating SBOM generation and automated vulnerability scanning directly within pipelines ensures that risks are identified early in the lifecycle.

Option B is correct because it reflects recommended practices from cloud native platform engineering standards: SBOMs provide a transparent inventory of all software components, including dependencies, which is crucial for vulnerability management, license compliance, and supply chain security. By automating these steps in CI/CD, teams can maintain both velocity and security without manual overhead.

Option A downplays the relevance of SBOMs for platform software, which is inaccurate because platform components (like Kubernetes operators, ingress controllers, or logging agents) are equally susceptible to vulnerabilities. Option C dismisses automation in favor of periodic audits, which contradicts the shift-left security principle. Option D misunderstands CI/CD's purpose: security must be integrated, not separated.


--- CNCF Supply Chain Security Whitepaper

--- CNCF Platforms Whitepaper

--- Cloud Native Platform Engineering Study Guide

Contribute your Thoughts:

0/2000 characters
Stephen
3 months ago
A makes sense, but platform software still needs attention.
upvoted 0 times
...
Pearlie
3 months ago
I disagree with C. Security can't be an afterthought!
upvoted 0 times
...
Cordelia
4 months ago
Wait, D sounds off. Manual processes after deployment? Really?
upvoted 0 times
...
Glendora
4 months ago
Totally agree with B! Automation is the way to go.
upvoted 0 times
...
Christiane
4 months ago
B is spot on! Early detection is key.
upvoted 0 times
...
Kerrie
4 months ago
I have a nagging feeling that option C is a common misconception; slowing down the pipeline for security checks seems counterproductive.
upvoted 0 times
...
Annita
4 months ago
I practiced a question similar to this, and I think the idea of automating security checks in the pipeline is crucial, which points me towards option B again.
upvoted 0 times
...
Gerald
5 months ago
I'm not entirely sure, but I feel like option A might be downplaying the importance of SBOM for platform software.
upvoted 0 times
...
Kiley
5 months ago
I remember discussing how CI/CD pipelines should ideally integrate security practices, so I think option B makes the most sense.
upvoted 0 times
...
Karl
5 months ago
I'm leaning towards option B. Automating those security checks within the pipeline seems like a smart way to ensure the platform software is secure and the components are well-documented.
upvoted 0 times
...
Joni
5 months ago
Option C seems reasonable to me. Slowing down the pipeline with extra steps could be problematic. Maybe those activities are better suited for separate audits.
upvoted 0 times
...
Veda
5 months ago
I'm a bit confused by the question. Aren't CI/CD pipelines just for automating deployments? I'm not sure how SBOM and security scanning fit in there.
upvoted 0 times
...
Marget
5 months ago
I think option B sounds like the best approach. Integrating SBOM and security scanning into the CI/CD pipeline makes a lot of sense to catch issues early.
upvoted 0 times
...

Save Cancel