QuestionQ56
Security EngineeringDuring DAST scans, applications repeatedly report code defects in open-source libraries used to build web applications. Most defects result from libraries with known vulnerabilities, and these defects are delaying product deployments. Which of the following is the best way to identify these issues earlier in the life cycle?
- A Directing application logs to the SIEM for continuous monitoring
- B Modifying the WAF polices to block against known vulnerabilities
- C Completing an IAST scan against the web application
- D Using a software dependency management solution
Community Discussion