Courseiva

200-901 Application Deployment and Security Practice Question

A CI/CD pipeline includes stages for security scanning. Which TWO tools or services are specifically designed for dependency vulnerability scanning?

⚠ Common exam trap

Cisco often tests the distinction between tools that perform a specific security function (like dependency scanning) versus general-purpose CI/CD or container tools that can only facilitate security scanning through external integrations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Snyk

Snyk (A) is a security platform whose core capability is scanning open-source dependencies and container images for known vulnerabilities, making it a purpose-built dependency vulnerability scanner for CI/CD pipelines. Dependabot (D) is GitHub's native service that monitors a project's dependency manifests (e.g., package.json, requirements.txt, pom.xml) and raises alerts or pull requests when vulnerable or outdated packages are detected, so it is also specifically designed for dependency vulnerability scanning. Kubernetes (B) is a container orchestration platform, not a vulnerability scanner, so it does not belong. Jenkins (C) is a CI/CD automation server that can invoke scanners but does not itself perform dependency vulnerability scanning. Docker (E) is a containerization platform for building and running images, not a dependency vulnerability scanning tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Snyk

    Why this is correct

    Snyk scans manifest and lock files against vulnerability databases, flagging known CVEs in third-party packages and their transitive dependencies. This directly satisfies the pipeline's dependency vulnerability scanning stage, unlike SAST or container image scanning tools.

  • ✗

    Kubernetes

    Why it's wrong here

    Kubernetes orchestrates containerised workloads; it performs no dependency analysis of package manifests or lockfiles, so it cannot detect vulnerable libraries. It is tempting because pipelines deploy to Kubernetes and security scanning often runs as a cluster job, but the orchestrator itself is the deployment target, not a scanner such as OWASP Dependency-Check or Snyk.

  • ✗

    Jenkins

    Why it's wrong here

    Jenkins is a CI/CD orchestration server that executes pipeline stages; it contains no dependency vulnerability database or scanning engine of its own. Scanning requires plugins wrapping tools such as OWASP Dependency-Check or Snyk. Jenkins is tempting because it hosts the scanning stage, but hosting a stage is not performing the scan.

  • ✓

    Dependabot

    Why this is correct

    Dependabot parses dependency manifests, compares versions against the GitHub Advisory Database, and raises alerts or pull requests for vulnerable packages. This satisfies the dependency vulnerability scanning requirement by detecting known CVEs in third-party libraries within the CI/CD pipeline.

  • ✗

    Docker

    Why it's wrong here

    Docker builds and runs container images; it performs no dependency analysis. Dependency vulnerability scanning requires tools such as OWASP Dependency-Check, Snyk or Trivy that inspect package manifests against vulnerability databases. Docker is tempting because pipeline stages run inside containers, but containerisation is unrelated to scanning dependencies.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.