easyMultiple Choice
CS0-003 Practice Question: A supplier provides a software product used in a…
A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For control selection, Which control best addresses the stated weakness without hiding risk?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between operational artifacts (like DNS records) and software composition artifacts (like SBOMs), trapping candidates who confuse network visibility with application-level visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A software bill of materials
A software bill of materials (SBOM) provides a formal, machine-readable inventory of all components, libraries, and versions used in a software product. This directly gives the security team the visibility needed for vulnerability management in a regulated environment, aligning with frameworks like NIST SP 800-53 and Executive Order 14028.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A DNS MX record report
Why it's wrong here
DNS MX records identify mail exchangers for a domain, revealing nothing about libraries embedded in a supplied product. It is tempting because DNS records are quick to request from a supplier and appear security-relevant, but they map mail routing, whereas the stated weakness requires a software bill of materials listing components and versions.
- ✓
A software bill of materials
Why this is correct
A software bill of materials enumerates every included library and its version, directly satisfying the requirement for visibility into third-party components within the regulated product. This transparency lets the security team identify vulnerable or outdated dependencies, supporting accurate risk assessment rather than concealing exposure behind vendor assurances.
- ✗
A building floor plan
Why it's wrong here
A building floor plan shows physical layout and facility access paths, not the libraries or versions compiled into the supplier's software. It is tempting because physical controls fall within supplier assurance questionnaires, but the stem's weakness is component transparency, which only an SBOM or software composition analysis report addresses.
- ✗
A password complexity screenshot only
Why it's wrong here
A password complexity screenshot evidences only authentication policy on one account, giving no visibility into bundled libraries or their versions. It is tempting because password controls are easy to evidence for compliance, but they address credential strength, not the third-party component inventory that software composition analysis or an SBOM would provide.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
Key term
SBOM
An SBOM is a formal, machine-readable inventory of all software components and dependencies used in a software application or system.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.