QuestionQ9

Vulnerability Management

Before merging with a software company, the acquiring company’s legal team requires a detailed software scan to determine whether the entire code base uses open-source or paid-licensed libraries. The vulnerability management analyst must provide this report. Which of the following scan methods best meets this requirement?

Explanation

Software composition analysis (SCA) identifies third-party and open-source components in a codebase and can determine the license or licenses associated with each component. This supports a legal review of open-source and paid-licensed library usage.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!