CAS-003 · Question #644
A development team releases updates to an application regularly. The application is compiled with several standard open-source security products that require a minimum version for compatibility…
The correct answer is C. The change logs for the third-party libraries should be reviewed for security patches, which may. Reviewing change logs of third-party open-source libraries identifies when security patches have been released, enabling developers to update dependencies to patched versions that still meet the minimum compatibility requirements. This is a Software Composition Analysis (SCA)…
Question
A development team releases updates to an application regularly. The application is compiled with several standard open-source security products that require a minimum version for compatibility. During the security review portion of the development cycle, which of the following should be done to minimize possible application vulnerabilities?
Options
- AThe developers should require an exact version of the open-source security products, preventing
- BThe application development team should move to an Agile development approach to identify
- CThe change logs for the third-party libraries should be reviewed for security patches, which may
- DThe application should eliminate the use of open-source libraries and products to prevent known
How the community answered
(38 responses)- A13% (5)
- B11% (4)
- C74% (28)
- D3% (1)
Explanation
Reviewing change logs of third-party open-source libraries identifies when security patches have been released, enabling developers to update dependencies to patched versions that still meet the minimum compatibility requirements. This is a Software Composition Analysis (SCA) best practice that directly reduces vulnerability exposure. Answer A (requiring exact library versions) prevents security updates from being applied, freezing the application on potentially vulnerable versions. Answer B (switching to Agile) is a process change that does not directly address third-party library vulnerabilities. Answer D (eliminating open-source libraries) is impractical and does not inherently improve security, as closed-source software also has vulnerabilities. Change log review is the targeted, practical control.
Topics
Community Discussion
No community discussion yet for this question.