Courseiva
Security Architecture →mediumMultiple Select

CAS-004 Security Architecture Practice Question

A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)

⚠ Common exam trap

CAS-005 often tests the distinction between SBOM as a component inventory plus dependency/vulnerability analysis versus generic security activities (pentesting, background checks, flow logs) that sound security-related but have nothing to do with software composition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

List of all open-source components and their versions

Option C is correct because an SBOM's core purpose is to enumerate every software component — including open-source libraries and their exact versions — so that downstream consumers can identify what is inside a product and trace provenance. Option E is correct because SBOMs enable dependency analysis, allowing organizations to correlate listed components and versions against vulnerability databases (e.g., NVD/CVE feeds) to detect known vulnerabilities in the supply chain. Together, these two form the essential SBOM strategy: knowing what components exist and analyzing their dependencies for risk. Option A (penetration testing results) is a point-in-time security assessment, not a component inventory, so it is not an SBOM element. Option B (employee background checks) is a personnel security control unrelated to software composition. Option D (network flow logs) captures runtime traffic metadata, not the software components or dependencies that an SBOM documents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Penetration testing results

    Why it's wrong here

    Penetration testing probes running systems for exploitable weaknesses; it produces no component inventory, so it cannot populate or validate an SBOM. It is tempting because testing is part of assurance, and would be correct where the objective is discovering vulnerabilities rather than tracking software constituents.

  • ✗

    Employee background checks

    Why it's wrong here

    Background checks vet personnel trustworthiness, not the components inside delivered software, so they contribute nothing to inventorying dependencies. They are tempting because supply chain programmes do address insider risk; they would be correct when the requirement is personnel security screening rather than SBOM component transparency.

  • ✓

    List of all open-source components and their versions

    Why this is correct

    An SBOM must enumerate every open-source library and its exact version, because version data is what lets you map components to advisories and licences. Without this inventory, the supply chain constraint of knowing what ships inside your software cannot be met.

  • ✗

    Network flow logs

    Why it's wrong here

    Network flow logs record connection metadata between hosts, revealing nothing about the components, libraries or dependencies compiled into an artefact, so they cannot populate an SBOM. They are tempting because flow telemetry genuinely supports supply chain monitoring for anomalous egress or command-and-control traffic after deployment, which is a detection control rather than an inventory one.

  • ✓

    Dependency analysis to identify known vulnerabilities

    Why this is correct

    Dependency analysis correlates the SBOM inventory against vulnerability databases, exposing transitive components that inherit risk. This satisfies the stem's requirement to identify known vulnerabilities across the supply chain, turning a static component list into actionable exposure data.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.