To detect when common open-source libraries are introduced into the codebase, which tool should be integrated into the build pipeline?
Choose an answer
Tap an option to check your answer.
Correct answer: WhiteSource.
Why this is the answer
WhiteSource (now Mend) is a Software Composition Analysis (SCA) tool specifically designed to identify and manage open-source components within a codebase. It scans for known vulnerabilities, license compliance issues, and outdated libraries, making it ideal for detecting when common open-source libraries are introduced. OWASP ZAP is a dynamic application security testing (DAST) tool used for finding vulnerabilities in running web applications, not for scanning source code for open-source components. SourceGear Vault is a version control system, not a security or open-source management tool. "No adjustment required" is incorrect because a dedicated SCA tool is needed for this specific detection.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed