CAS-004 Security Architecture Practice Question
A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?
⚠ Common exam trap
CAS-005 often tests the specific practices that directly address supply chain security versus general security controls. Candidates may select network segmentation or RASP because they sound security-related, but they do not address supply chain risks in the CI/CD pipeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dependency analysis
Dependency analysis (B) is correct because it inspects third-party libraries and transitive dependencies for known CVEs (e.g., via SCA tools like OWASP Dependency-Check, Snyk, or Trivy) before artifacts are built, directly protecting the software supply chain from vulnerable or malicious packages. Container image scanning (C) is correct because it examines image layers and installed packages against vulnerability databases (e.g., Clair, Trivy, Grype) so compromised base images or components are caught in the CI/CD pipeline before deployment. Software Bill of Materials (E) is correct because an SBOM (e.g., SPDX or CycloneDX format) provides a machine-readable inventory of components and dependencies, enabling provenance tracking, rapid impact analysis when new CVEs emerge, and compliance with supply chain mandates. Network segmentation (A) is a runtime infrastructure control that limits lateral movement but does not secure the build and delivery pipeline itself, and runtime application self-protection (D) is a runtime defense that detects and blocks attacks in a running application, not a CI/CD supply chain practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network segmentation
Why it's wrong here
Network segmentation isolates workloads at the infrastructure layer; it does not verify artefact provenance, sign commits, or scan dependencies, so it cannot secure the software supply chain. It is tempting because segmentation limits lateral movement generally, and would be correct when containing a compromised host within a flat network.
- ✓
Dependency analysis
Why this is correct
Dependency analysis inspects third-party libraries and transitive packages for known CVEs before they enter the build, directly satisfying the supply chain security requirement. It catches vulnerable or malicious components at the point of integration, preventing compromised dependencies from reaching production artefacts.
- ✓
Container image scanning
Why this is correct
Container image scanning inspects image layers and installed packages for known vulnerabilities before deployment, satisfying the supply chain security requirement. It detects compromised or outdated base images and dependencies, blocking risky artefacts from progressing through the CI/CD pipeline to production.
- ✗
Runtime application self-protection
Why it's wrong here
RASP instruments a running application to block attacks at execution time; it does not address supply chain integrity, which concerns build artefacts, dependencies and provenance before deployment. It is tempting because RASP hardens production workloads, and would be correct when defending a deployed application against runtime exploitation attempts.
- ✓
Software Bill of Materials (SBOM)
Why this is correct
An SBOM enumerates every component and dependency in the software artefact, giving the traceability that supply chain security demands. It lets the team rapidly identify exposure when a new upstream vulnerability is disclosed, satisfying the requirement to know precisely what ships.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.