What is the purpose of an SBOM (Software Bill of Materials) in the context of supply chain security?
An SBOM (Software Bill of Materials) is a formal, structured record that enumerates every software component, library, package, and dependency included in an artifact, along with metadata such as version numbers and often licenses. It provides a complete supply-chain inventory, making it possible to trace exactly which code is present and why it was included. This transparency is foundational for license compliance, security analysis, and incident response.
Why this answer
An SBOM is a formal, machine-readable inventory of all software components, libraries, and dependencies that make up an artifact such as a container image. Its purpose is to provide transparency into the supply chain so that when a new vulnerability is disclosed, you can quickly determine whether your artifact contains the affected component. It does not itself perform signing, scanning, or runtime enforcement.
Exam trap
The trap here is confusing the purpose of an SBOM with that of a vulnerability scanner or a signing tool; candidates often pick 'scan images for vulnerabilities' because SBOMs are used in vulnerability management, but the SBOM itself is only the inventory.
How to eliminate wrong answers
Option A is wrong because signing container images is done by tools like cosign or Notary, not by an SBOM; an SBOM is a list, not a signature. Option B is wrong because scanning images for vulnerabilities is performed by scanners like Trivy or Clair, which may consume an SBOM but the SBOM itself is not a scanner. Option D is wrong because runtime security policies are enforced by tools like Falco, AppArmor, or seccomp, not by an SBOM.