Courseiva
easyMultiple Choice

CS0-003 Practice Question: A supplier provides a software product used in a…

A supplier provides a software product used in a regulated environment. The security team wants visibility into included libraries and versions. What should they request? For control selection, Which control best addresses the stated weakness without hiding risk?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between operational artifacts (like DNS records) and software composition artifacts (like SBOMs), trapping candidates who confuse network visibility with application-level visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A software bill of materials

A software bill of materials (SBOM) provides a formal, machine-readable inventory of all components, libraries, and versions used in a software product. This directly gives the security team the visibility needed for vulnerability management in a regulated environment, aligning with frameworks like NIST SP 800-53 and Executive Order 14028.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A DNS MX record report

    Why it's wrong here

    DNS MX records identify mail exchangers for a domain, revealing nothing about libraries embedded in a supplied product. It is tempting because DNS records are quick to request from a supplier and appear security-relevant, but they map mail routing, whereas the stated weakness requires a software bill of materials listing components and versions.

  • ✓

    A software bill of materials

    Why this is correct

    A software bill of materials enumerates every included library and its version, directly satisfying the requirement for visibility into third-party components within the regulated product. This transparency lets the security team identify vulnerable or outdated dependencies, supporting accurate risk assessment rather than concealing exposure behind vendor assurances.

  • ✗

    A building floor plan

    Why it's wrong here

    A building floor plan shows physical layout and facility access paths, not the libraries or versions compiled into the supplier's software. It is tempting because physical controls fall within supplier assurance questionnaires, but the stem's weakness is component transparency, which only an SBOM or software composition analysis report addresses.

  • ✗

    A password complexity screenshot only

    Why it's wrong here

    A password complexity screenshot evidences only authentication policy on one account, giving no visibility into bundled libraries or their versions. It is tempting because password controls are easy to evidence for compliance, but they address credential strength, not the third-party component inventory that software composition analysis or an SBOM would provide.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.