Which service should you use to verify that the approximately 50 open-source libraries used by an Azure DevOps build pipeline comply with your company's licensing requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Black Duck.
Why this is the answer
Black Duck is a Software Composition Analysis (SCA) tool that specializes in identifying open-source components within your code, including their licenses, vulnerabilities, and compliance issues. It's designed to scan and report on the open-source libraries used in your projects, making it ideal for verifying licensing requirements for numerous open-source components. NuGet and Maven are package managers primarily used for dependency management in .NET and Java ecosystems, respectively; they don't inherently provide licensing compliance scanning. Helm is a package manager for Kubernetes, used for managing Kubernetes applications, not for open-source license compliance of application dependencies.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed