
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 5
Software Composition Analysis (SCA) ECDE Practice Questions (Page 2)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
9concepts
Questions 6–10
- 6
An SCA tool reports that a dependency version is vulnerable according to the NVD. However, the development team argues that the vulnerable function is not used in their code. What should the security team do to validate this claim?
Select an answer first - 7
A startup is building a web application using many open-source libraries. The CTO wants to understand the security and legal risks associated with these dependencies before launch. Which practice provides the most comprehensive view?
Select an answer first - 8
Which of the following is a key role of Software Composition Analysis (SCA) in the software development lifecycle?
Select an answer first - 9
Which public database is the U.S. government's primary repository for publicly disclosed software vulnerabilities?
Select an answer first - 10
An SCA tool reports a vulnerability in a dependency, but the CVE entry in the NVD has a status of 'Disputed' and the vendor claims it is not a vulnerability. The dependency is widely used and the vulnerable function is called in the application's code. What is the best approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.