ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A development team deploys containerized microservices to a managed Kubernetes cluster in the public cloud. Their CI/CD pipeline already runs static code analysis in the build stage and dynamic application security testing in the staging environment. After a recent incident caused by a vulnerable open-source component, management asks for earlier detection of third-party library flaws and license violations without waiting for the code to be executed. Which additional assurance technique should be added earliest in the pipeline to meet this requirement?
Attach an Interactive Application Security Testing agent to the staging environment.
Schedule quarterly external penetration tests after production release.
Introduce Software Composition Analysis to scan dependency manifests during the build phase.
Apply Kubernetes pod security policies to restrict container capabilities at runtime.
Software Composition Analysis (SCA) inventories all open-source and third-party components referenced during the build, compares their versions against vulnerability databases, and checks license metadata. Because it operates on dependency manifests or container layers, it can run immediately after packages are downloaded, providing rapid feedback before the application is compiled or executed. Interactive Application Security Testing relies on instrumented runtime behavior, so findings arrive later. Periodic penetration tests and Kubernetes pod security policies improve security, but neither focuses on systematically flagging vulnerable or non-compliant libraries during the build process.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Software Composition Analysis (SCA)?
Open an interactive chat with Bash
Why is SCA preferable to Interactive Application Security Testing (IAST) in this scenario?
Open an interactive chat with Bash
How does SCA help with license compliance?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .