As part of a security validation strategy in Azure DevOps, you need to identify package dependencies that have known security issues which can be resolved by updating the packages. Which tool should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: SonarQube.
Why this is the answer
SonarQube is a static analysis tool that can identify security vulnerabilities, code smells, and bugs in your code, including outdated or vulnerable package dependencies. It integrates with Azure DevOps pipelines to provide continuous code quality and security analysis. Octopus Deploy is a release automation tool. Jenkins is an open-source automation server for CI/CD. Gradle is a build automation tool. While these tools can be part of a DevOps pipeline, they do not inherently perform static code analysis for security vulnerabilities in package dependencies like SonarQube does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed