Q35Infrastructure and AutomationMultiple answers
Which two conditions are identified by dependency-checking tools used in continuous-integration environments, such as OWASP? (Choose two.)
Select 2 answers.
← → navigate · a answer
Community votes
Discussion · 9
11
I agree with A and E:
OWASP Dependency Check is a well-known open-source tool that can track dependencies in your project and identify components with dependencies, and it checks whether there are any known, publicly disclosed vulnerabilities.
Source code analysis tools, also called Static Application Security Testing (SAST) Tools, are meant to analyze source code and/or compiled versions of code to help find security flaws. They are useful for things that such tools can automatically find with high confidence, such as buffer overflows, SQL Injection Flaws, and so forth
5
A & E are fine
A, E 3
Selected Answer: AE
Flagship Projects:
- OWASP Amass
- OWASP Application Security Verification Standard
- OWASP Cheat Sheet Series
- OWASP CSRFGuard
- OWASP CycloneDX
- OWASP Defectdojo
- OWASP Dependency-Check
- OWASP Dependency-Track
- OWASP Juice Shop
- OWASP Mobile Application Security
- OWASP ModSecurity Core Rule Set
- OWASP OWTF
- OWASP SAMM
- OWASP Security Knowledge Framework
- OWASP Security Shepherd
- OWASP Top Ten
- OWASP Web Security Testing Guide
- OWASP ZAP
2
I’d stick with A and E
A, C 2
Selected Answer: AC
A. Publicly disclosed vulnerabilities tied to dependencies
This is correct because:
Security vulnerability scanning is a core part of dependency checkers
They compare against databases of known CVEs and security advisories
This helps avoid using components with known security problems
C. Incompatible licenses in dependencies
This is also correct because:
License compliance is a key part of dependency management
Tools check for conflicts between different open source licenses
This prevents legal issues from incompatible license combinations
A, E 1
Selected Answer: AE
i agree with blezzzo.
1
my thought is that A and D is correct
tools like owasp dependency check do not cover buffer overflow vulnerability
1
I would go with A and C, because OWASP dependency-check is not a SAST, I mean it is not meant to catch runtime issues like buffer overflows
A, C 1
Selected Answer: AC
OWASP Dependency track looks for known vulnerabilities and license risk
https://owasp.org/www-project-dependency-track/