nerdexam
CompTIA

CAS-003 · Question #599

Which of the following are the MOST likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two.)

The correct answer is A. Unsecure protocols C. Weak passwords. NOTE: The listed correct answers (A and C - unsecure protocols and weak passwords) appear to be incorrect for this question. The question asks specifically about vectors for the unintentional inclusion of vulnerable code in software releases. The correct answers are D (included…

Technical Integration of Enterprise Security

Question

Which of the following are the MOST likely vectors for the unauthorized or unintentional inclusion of vulnerable code in a software company's final software releases? (Choose two.)

Options

  • AUnsecure protocols
  • BUse of penetration-testing utilities
  • CWeak passwords
  • DIncluded third-party libraries
  • EVendors/supply chain
  • FOutdated anti-malware software

How the community answered

(34 responses)
  • A
    91% (31)
  • B
    3% (1)
  • E
    3% (1)
  • F
    3% (1)

Explanation

NOTE: The listed correct answers (A and C - unsecure protocols and weak passwords) appear to be incorrect for this question. The question asks specifically about vectors for the unintentional inclusion of vulnerable code in software releases. The correct answers are D (included third-party libraries) and E (vendors/supply chain). Open-source third-party libraries (e.g., the Log4j vulnerability) and compromised supply chain vendors (e.g., SolarWinds) are the primary real-world vectors for introducing vulnerable or malicious code into a software company's final product. Unsecure protocols and weak passwords are operational security issues, not mechanisms by which vulnerable code enters a build pipeline.

Topics

#supply chain#third-party libraries#SDLC#software vulnerabilities

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice