CAS-004 Security Architecture Practice Question
A security architect is reviewing supply chain security for a software product. Which TWO artifacts are most important for verifying the integrity and provenance of third-party components?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software bill of materials (SBOM)
Option B, the software bill of materials (SBOM), is correct because it enumerates every third-party and open-source component, library, and version in the product, which is the foundation for verifying provenance and detecting tampered or vulnerable dependencies. Option C, the dependency analysis report, is correct because it maps direct and transitive dependencies and flags known vulnerabilities, license conflicts, and unexpected or unvetted components, directly supporting integrity verification of the supply chain. Together, the SBOM provides the authoritative component inventory while the dependency analysis validates those components against known-good and known-bad data. Option A, penetration test results, is not correct because pen testing assesses exploitable weaknesses in a running system, not the provenance or integrity of third-party components. Option D, network flow logs, is not correct because they record traffic metadata for monitoring and forensics, not component-level supply chain integrity. Option E, database encryption configuration, is not correct because it addresses data-at-rest protection and is unrelated to verifying third-party component provenance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Penetration test results
Why it's wrong here
Penetration test results describe discovered weaknesses, not the origin or integrity of a component. They tempt because they evidence supplier due diligence, yet provenance requires an SBOM and signed attestations such as SLSA or Sigstore, which bind an artifact to its build source.
- ✓
Software bill of materials (SBOM)
Why this is correct
An SBOM enumerates every component and version in the product, giving the inventory needed to trace third-party dependencies. Combined with provenance attestation, it lets the architect verify what was supplied and detect tampering or unexpected inclusions, satisfying the integrity and provenance requirement.
- ✓
Dependency analysis report
Why this is correct
Dependency analysis maps transitive libraries and their versions, revealing hidden third-party components and known vulnerabilities. It supplies the provenance chain and integrity evidence for each dependency, which is exactly what the stem requires when verifying third-party components in the supply chain.
- ✗
Network flow logs
Why it's wrong here
Network flow logs record traffic metadata between hosts, not the composition, hashes or build origin of third-party components, so they cannot verify integrity or provenance. They are tempting because they support incident investigation and detecting anomalous egress, which is the right choice when tracing suspicious outbound connections after a breach.
- ✗
Database encryption configuration
Why it's wrong here
Database encryption configuration documents at-rest protection settings, revealing nothing about which third-party libraries were included or where they came from. It is tempting because encryption configuration is genuine supply chain hardening evidence, and would be the correct artefact when demonstrating that stored component data is encrypted.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.