Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified DevSecOps Engineer

Domain 2Objective 5

Software Composition Analysis (SCA) ECDE Practice Questions (Page 8)

Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.

44questions here
9free pages
9concepts

Questions 36–40

  1. 36foundation · easy

    When a patched version of a vulnerable dependency is not available, which of the following is a possible remediation strategy?

    Select an answer first
  2. 37foundation · easy

    Why is license compliance an important part of Software Composition Analysis?

    Select an answer first
  3. 38application · medium

    A company is considering using a library that is licensed under the Apache 2.0 license. The company's policy allows permissive licenses but requires attribution. What should the team do to comply with the license?

    Select an answer first
  4. 39application · medium

    An organization's legal team requires that all open-source dependencies used in a new product must have licenses compatible with the company's proprietary distribution model. The development team is about to add a library that is licensed under the GNU General Public License (GPL). What should the team do first?

    Select an answer first
  5. 40foundation · easy

    Which file is most commonly used to identify the exact versions of direct and transitive dependencies in a JavaScript (npm) project?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.