QuestionQ79

DevSecOps Pipeline-Operate and Monitor Stage

Frances Fisher joined TerraWolt Pvt. Ltd. as a DevSecOps engineer in 2020. On February 1, 2022, the organization suffered a cybersecurity attack in which the attacker targeted network and application vulnerabilities and compromised some important functionality of the application.

To protect the organization against similar attacks, Frances adopted a vulnerability management and assessment solution with the following characteristics:

  • Flexible, accurate, and low maintenance
  • Continuously scans network and application vulnerabilities
  • Provides daily updates
  • Uses specialized testing methodologies to catch the maximum number of detectable vulnerabilities

Based on this information, which of the following tools is Frances using?

  • A Shadow Daemon
  • B BeSECURE
  • C Black Duck
  • D SonarQube
Explanation

BeSECURE is described by its vendor (Beyond Security) as a flexible, accurate, and low-maintenance vulnerability management and assessment solution that continuously scans networks and applications, delivers daily vulnerability signature updates, and employs specialized testing methodologies to maximize detection of vulnerabilities — precisely matching the scenario's requirements. The other options serve different purposes: Shadow Daemon is a web application firewall/intrusion detection tool, Black Duck focuses on open-source software composition analysis, and SonarQube is a static code quality and analysis tool, none of which match the continuous network/application vulnerability scanning capability described.

Community Discussion

No comments yet. Be the first to start the discussion!