hardMultiple Choice
CS0-003 SCA Practice Question
A development team wants to find vulnerable open-source libraries before deployment. Which control best fits this stage? For control selection, Which control best addresses the stated weakness without hiding risk?
⚠ Common exam trap
CompTIA often tests the distinction between vulnerability scanning (SCA) and other security controls like network monitoring or physical security, so the trap here is confusing a general security practice (e.g., backups or access reviews) with a specific software dependency scanning control that directly addresses the stated weakness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Software composition analysis in the CI/CD pipeline
Software composition analysis (SCA) is the correct control because it automatically scans the project's dependencies against known vulnerability databases (e.g., NVD, GitHub Advisory Database) to identify vulnerable open-source libraries before deployment. Integrating SCA into the CI/CD pipeline ensures that vulnerabilities are caught early in the development lifecycle, aligning with the shift-left security principle without suppressing or masking risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireless spectrum analysis
Why it's wrong here
Wireless spectrum analysis surveys RF interference and rogue access points; it inspects no source code, package manifests or dependency trees, so it cannot detect vulnerable open-source libraries. It is tempting as a monitoring control, but it is the correct choice when diagnosing WLAN coverage, channel overlap or unauthorised radios.
- ✗
Physical badge access reviews
Why it's wrong here
Physical badge access reviews audit who enters data centres; they examine no build artefacts, lockfiles or dependency versions, so vulnerable libraries pass into deployment undetected. It is tempting as an access control, but it is the correct choice when validating that only authorised personnel retain physical entry to sensitive facilities.
- ✗
Database transaction log backups
Why it's wrong here
Database transaction log backups support recovery and point-in-time restore; they inspect no package dependencies, so vulnerable open-source libraries remain unidentified before deployment. It is tempting as a data-protection control, but it is the correct choice when the requirement is restoring or auditing database changes after corruption or loss.
- ✓
Software composition analysis in the CI/CD pipeline
Why this is correct
Software composition analysis inventories open-source dependencies and their known CVEs, satisfying the requirement to find vulnerable libraries before deployment. Running it in the CI/CD pipeline blocks risky builds at the earliest feasible stage rather than after release.
Go deeper
Related to this question
Learn chapter
Vulnerability Management Workflow
Key term
SCA
SCA (Software Composition Analysis) is a security testing method that automatically identifies open-source components, libraries, and dependencies in software to find known vulnerabilities and license compliance issues.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.