CAS-004 Security Architecture Practice Question
A security architect is designing a supply chain security program. Which TWO of the following are essential components of a software bill of materials (SBOM) strategy? (Select TWO.)
⚠ Common exam trap
CAS-005 often tests the distinction between SBOM as a component inventory plus dependency/vulnerability analysis versus generic security activities (pentesting, background checks, flow logs) that sound security-related but have nothing to do with software composition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
List of all open-source components and their versions
Option C is correct because an SBOM's core purpose is to enumerate every software component — including open-source libraries and their exact versions — so that downstream consumers can identify what is inside a product and trace provenance. Option E is correct because SBOMs enable dependency analysis, allowing organizations to correlate listed components and versions against vulnerability databases (e.g., NVD/CVE feeds) to detect known vulnerabilities in the supply chain. Together, these two form the essential SBOM strategy: knowing what components exist and analyzing their dependencies for risk. Option A (penetration testing results) is a point-in-time security assessment, not a component inventory, so it is not an SBOM element. Option B (employee background checks) is a personnel security control unrelated to software composition. Option D (network flow logs) captures runtime traffic metadata, not the software components or dependencies that an SBOM documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Penetration testing results
Why it's wrong here
Penetration testing probes running systems for exploitable weaknesses; it produces no component inventory, so it cannot populate or validate an SBOM. It is tempting because testing is part of assurance, and would be correct where the objective is discovering vulnerabilities rather than tracking software constituents.
- ✗
Employee background checks
Why it's wrong here
Background checks vet personnel trustworthiness, not the components inside delivered software, so they contribute nothing to inventorying dependencies. They are tempting because supply chain programmes do address insider risk; they would be correct when the requirement is personnel security screening rather than SBOM component transparency.
- ✓
List of all open-source components and their versions
Why this is correct
An SBOM must enumerate every open-source library and its exact version, because version data is what lets you map components to advisories and licences. Without this inventory, the supply chain constraint of knowing what ships inside your software cannot be met.
- ✗
Network flow logs
Why it's wrong here
Network flow logs record connection metadata between hosts, revealing nothing about the components, libraries or dependencies compiled into an artefact, so they cannot populate an SBOM. They are tempting because flow telemetry genuinely supports supply chain monitoring for anomalous egress or command-and-control traffic after deployment, which is a detection control rather than an inventory one.
- ✓
Dependency analysis to identify known vulnerabilities
Why this is correct
Dependency analysis correlates the SBOM inventory against vulnerability databases, exposing transitive components that inherit risk. This satisfies the stem's requirement to identify known vulnerabilities across the supply chain, turning a static component list into actionable exposure data.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.