
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 5
Software Composition Analysis (SCA) ECDE Practice Questions (Page 3)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
9concepts
Questions 11–15
- 11
A company must provide a Software Bill of Materials (SBOM) for a legacy application that was built without any dependency management tools. The source code is available, but there are no lock files or manifests. The security team needs to generate an SBOM for the next audit. What is the most reliable approach?
Select an answer first - 12
An SCA scan reports a high-severity vulnerability in a transitive dependency of a Java application. The security team investigates and finds that the vulnerable code path is never executed because the application does not use the affected class. What should the team do?
Select an answer first - 13
Why is an SBOM important for vulnerability tracking?
Select an answer first - 14
A Python application uses a popular library that has a known critical vulnerability. The latest patched version of the library is available, but it requires a newer version of Python than the application currently uses. The team cannot upgrade the Python runtime in the current release cycle. What is the most appropriate remediation strategy?
Select an answer first - 15
A critical vulnerability is disclosed in a widely used open-source library. The patched version is available, but it introduces a breaking API change that affects multiple modules in the application. The team must release a security fix within a week. What is the most balanced approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.