Courseiva
Security Architecture →hardMultiple Select

CAS-004 Security Architecture Practice Question

A DevSecOps team is integrating security into the CI/CD pipeline. Which THREE practices should be included to ensure supply chain security?

⚠ Common exam trap

CAS-005 often tests the specific practices that directly address supply chain security versus general security controls. Candidates may select network segmentation or RASP because they sound security-related, but they do not address supply chain risks in the CI/CD pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dependency analysis

Dependency analysis (B) is correct because it inspects third-party libraries and transitive dependencies for known CVEs (e.g., via SCA tools like OWASP Dependency-Check, Snyk, or Trivy) before artifacts are built, directly protecting the software supply chain from vulnerable or malicious packages. Container image scanning (C) is correct because it examines image layers and installed packages against vulnerability databases (e.g., Clair, Trivy, Grype) so compromised base images or components are caught in the CI/CD pipeline before deployment. Software Bill of Materials (E) is correct because an SBOM (e.g., SPDX or CycloneDX format) provides a machine-readable inventory of components and dependencies, enabling provenance tracking, rapid impact analysis when new CVEs emerge, and compliance with supply chain mandates. Network segmentation (A) is a runtime infrastructure control that limits lateral movement but does not secure the build and delivery pipeline itself, and runtime application self-protection (D) is a runtime defense that detects and blocks attacks in a running application, not a CI/CD supply chain practice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Network segmentation

    Why it's wrong here

    Network segmentation isolates workloads at the infrastructure layer; it does not verify artefact provenance, sign commits, or scan dependencies, so it cannot secure the software supply chain. It is tempting because segmentation limits lateral movement generally, and would be correct when containing a compromised host within a flat network.

  • ✓

    Dependency analysis

    Why this is correct

    Dependency analysis inspects third-party libraries and transitive packages for known CVEs before they enter the build, directly satisfying the supply chain security requirement. It catches vulnerable or malicious components at the point of integration, preventing compromised dependencies from reaching production artefacts.

  • ✓

    Container image scanning

    Why this is correct

    Container image scanning inspects image layers and installed packages for known vulnerabilities before deployment, satisfying the supply chain security requirement. It detects compromised or outdated base images and dependencies, blocking risky artefacts from progressing through the CI/CD pipeline to production.

  • ✗

    Runtime application self-protection

    Why it's wrong here

    RASP instruments a running application to block attacks at execution time; it does not address supply chain integrity, which concerns build artefacts, dependencies and provenance before deployment. It is tempting because RASP hardens production workloads, and would be correct when defending a deployed application against runtime exploitation attempts.

  • ✓

    Software Bill of Materials (SBOM)

    Why this is correct

    An SBOM enumerates every component and dependency in the software artefact, giving the traceability that supply chain security demands. It lets the team rapidly identify exposure when a new upstream vulnerability is disclosed, satisfying the requirement to know precisely what ships.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.