Courseiva
hardMultiple Choice

CS0-003 SCA Practice Question

A development team wants to find vulnerable open-source libraries before deployment. Which control best fits this stage? For control selection, Which control best addresses the stated weakness without hiding risk?

⚠ Common exam trap

CompTIA often tests the distinction between vulnerability scanning (SCA) and other security controls like network monitoring or physical security, so the trap here is confusing a general security practice (e.g., backups or access reviews) with a specific software dependency scanning control that directly addresses the stated weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Software composition analysis in the CI/CD pipeline

Software composition analysis (SCA) is the correct control because it automatically scans the project's dependencies against known vulnerability databases (e.g., NVD, GitHub Advisory Database) to identify vulnerable open-source libraries before deployment. Integrating SCA into the CI/CD pipeline ensures that vulnerabilities are caught early in the development lifecycle, aligning with the shift-left security principle without suppressing or masking risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wireless spectrum analysis

    Why it's wrong here

    Wireless spectrum analysis surveys RF interference and rogue access points; it inspects no source code, package manifests or dependency trees, so it cannot detect vulnerable open-source libraries. It is tempting as a monitoring control, but it is the correct choice when diagnosing WLAN coverage, channel overlap or unauthorised radios.

  • ✗

    Physical badge access reviews

    Why it's wrong here

    Physical badge access reviews audit who enters data centres; they examine no build artefacts, lockfiles or dependency versions, so vulnerable libraries pass into deployment undetected. It is tempting as an access control, but it is the correct choice when validating that only authorised personnel retain physical entry to sensitive facilities.

  • ✗

    Database transaction log backups

    Why it's wrong here

    Database transaction log backups support recovery and point-in-time restore; they inspect no package dependencies, so vulnerable open-source libraries remain unidentified before deployment. It is tempting as a data-protection control, but it is the correct choice when the requirement is restoring or auditing database changes after corruption or loss.

  • ✓

    Software composition analysis in the CI/CD pipeline

    Why this is correct

    Software composition analysis inventories open-source dependencies and their known CVEs, satisfying the requirement to find vulnerable libraries before deployment. Running it in the CI/CD pipeline blocks risky builds at the earliest feasible stage rather than after release.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.