Valid PT0-003 Dumps shared by ExamDiscuss.com for Helping Passing PT0-003 Exam! ExamDiscuss.com now offer the newest PT0-003 exam dumps, the ExamDiscuss.com PT0-003 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com PT0-003 dumps with Test Engine here:
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
Correct Answer: D
Software Composition Analysis (SCA) is used to analyze dependencies in applications and identify vulnerable open-source libraries. * Option A (VM - Virtual Machine) #: A VM is a computing environment, not a vulnerability detection tool. * Option B (IAST - Interactive Application Security Testing) #: IAST analyzes runtime behavior, but it does not specialize in detecting vulnerable libraries. * Option C (DAST - Dynamic Application Security Testing) #: DAST scans running applications for vulnerabilities, but it does not analyze open-source libraries. * Option D (SCA - Software Composition Analysis) #: Correct. * Identifies security flaws in dependencies. * Used for managing supply chain risks. # Reference: CompTIA PenTest+ PT0-003 Official Guide - Software Composition Analysis (SCA)