
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 5
Software Composition Analysis (SCA) ECDE Practice Questions (Page 7)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
9concepts
Questions 31–35
- 31
Which type of open-source license typically requires that derivative works be distributed under the same license?
Select an answer first - 32
Which of the following is a commonly used open-source Software Composition Analysis tool?
Select an answer first - 33
A security team wants to integrate SCA scanning into their CI pipeline for a .NET application. They need a tool that can be run from the command line, generate reports in a format that can be consumed by their dashboard, and fail the build on high-severity vulnerabilities. Which tool should they choose?
Select an answer first - 34
What is a Software Bill of Materials (SBOM)?
Select an answer first - 35
What is the primary purpose of Software Composition Analysis (SCA) in a DevSecOps pipeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.