
EC-CouncilCertified DevSecOps Engineer
Domain 2Objective 5
Software Composition Analysis (SCA) ECDE Practice Questions (Page 9)
Part of the Plan Stage: Threat Modeling and Pre-Commit Security domain, which makes up ~19% of our current practice bank.
44questions here
9free pages
9concepts
Questions 41–44
- 41
An SCA scan reports a vulnerability in a dependency, but the vulnerability is in a platform-specific module that is not used on the target operating system. The team is deploying to Linux, and the vulnerable module is for Windows. What should the team do?
Select an answer first - 42
A team is using OWASP Dependency-Check in their CI pipeline. They notice that the scan takes too long and is slowing down the pipeline. What is the most effective way to reduce scan time without losing vulnerability coverage?
Select an answer first - 43
A security team needs to choose an SCA tool for a multi-language monorepo that includes Java (Maven), Python (pip), and JavaScript (npm). The tool must be able to scan all three languages and integrate with their Jenkins pipeline. Which tool selection is most appropriate?
Select an answer first - 44
Which of the following is a common remediation action for a vulnerable open-source dependency?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECDE” is a trademark of its owner, used for identification only.