mediumMultiple Select
CS0-003 Practice Question: Which pipeline controls help prevent vulnerable…
Which pipeline controls help prevent vulnerable dependencies reaching production? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between pipeline-level controls (automated, code-focused) and physical or administrative controls, so candidates may mistakenly select a non-technical option like badge checks because they confuse 'pipeline' with general security procedures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SBOM generation and review for released builds
A is correct because SBOM (Software Bill of Materials) generation and review provides a detailed inventory of all components in a build, enabling teams to identify and block vulnerable dependencies before release. This aligns with supply chain security best practices, as SBOMs allow automated comparison against vulnerability databases (e.g., NVD) to enforce policy gates early in the pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SBOM generation and review for released builds
Why this is correct
Generating a Software Bill of Materials (SBOM) provides a comprehensive, machine-readable inventory of all third-party components, libraries, and dependencies within a software build. Reviewing these manifests allows security teams to track downstream risks, identify newly disclosed vulnerabilities in existing deployments, and ensure compliance with licensing and security standards.
- ✗
Manual badge checks at the office door
Why it's wrong here
Manual badge checks are a physical security control designed to prevent unauthorized personnel from entering a physical facility. They operate entirely outside the CI/CD pipeline and have no mechanism to inspect, analyze, or restrict vulnerable software dependencies or code libraries.
- ✓
Software composition analysis with policy gates
Why this is correct
Software Composition Analysis (SCA) tools automatically scan application source code and build artifacts to identify known vulnerabilities (CVEs) in open-source and third-party dependencies. By integrating policy gates, the CI/CD pipeline can automatically block builds or deployments that violate defined security thresholds, preventing vulnerable libraries from reaching production.
- ✗
DNS MX record rotation
Why it's wrong here
DNS Mail Exchanger (MX) records specify the mail servers responsible for accepting email messages on behalf of a domain. Rotating or modifying these records is an administrative task for email routing and has no bearing on application security, dependency management, or pipeline vulnerability scanning.
Visual reference
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.