Prior to a merger, the acquiring company's legal team requires a detailed scan of the software codebase to determine whether all code is using open-source libraries or paid licensed libraries. The vulnerability management analyst must provide this report. Which of the following scan methods would best fulfill this requirement?
AStatic application security testing (SAST)
BDynamic application security testing (DAST)
CSoftware composition analysis (SCA)
DRuntime application self-protection (RASP)
ECredentialed vulnerability scan
0
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion