Courseiva
mediumMultiple Select

CS0-003 Practice Question: Which pipeline controls help prevent vulnerable…

Which pipeline controls help prevent vulnerable dependencies reaching production? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between pipeline-level controls (automated, code-focused) and physical or administrative controls, so candidates may mistakenly select a non-technical option like badge checks because they confuse 'pipeline' with general security procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SBOM generation and review for released builds

A is correct because SBOM (Software Bill of Materials) generation and review provides a detailed inventory of all components in a build, enabling teams to identify and block vulnerable dependencies before release. This aligns with supply chain security best practices, as SBOMs allow automated comparison against vulnerability databases (e.g., NVD) to enforce policy gates early in the pipeline.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SBOM generation and review for released builds

    Why this is correct

    Generating a Software Bill of Materials (SBOM) provides a comprehensive, machine-readable inventory of all third-party components, libraries, and dependencies within a software build. Reviewing these manifests allows security teams to track downstream risks, identify newly disclosed vulnerabilities in existing deployments, and ensure compliance with licensing and security standards.

  • ✗

    Manual badge checks at the office door

    Why it's wrong here

    Manual badge checks are a physical security control designed to prevent unauthorized personnel from entering a physical facility. They operate entirely outside the CI/CD pipeline and have no mechanism to inspect, analyze, or restrict vulnerable software dependencies or code libraries.

  • ✓

    Software composition analysis with policy gates

    Why this is correct

    Software Composition Analysis (SCA) tools automatically scan application source code and build artifacts to identify known vulnerabilities (CVEs) in open-source and third-party dependencies. By integrating policy gates, the CI/CD pipeline can automatically block builds or deployments that violate defined security thresholds, preventing vulnerable libraries from reaching production.

  • ✗

    DNS MX record rotation

    Why it's wrong here

    DNS Mail Exchanger (MX) records specify the mail servers responsible for accepting email messages on behalf of a domain. Rotating or modifying these records is an administrative task for email routing and has no bearing on application security, dependency management, or pipeline vulnerability scanning.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.