A custom web application uses several open-source libraries. The host OS vulnerability scan is clean, but the application team suspects a vulnerable component is bundled inside the application package. Which scanning method should the analyst request?
Select an answer to reveal the explanation.
Short Explanation
Think of your app like a sandwich: the OS scan checks the bread, but dependency analysis opens it up to find the spoiled filling. If the vulnerable piece is an open-source library inside the app, you need to look at the app's ingredients, not the host. That's why dependency analysis wins here.
Full Explanation
Dependency analysis, often delivered through software composition analysis, inspects application manifests, lockfiles, and package metadata to enumerate embedded open-source components, then compares those components to vulnerability intelligence such as CVE entries and vendor advisories. This is the right method when the weakness is inside the application package rather than the operating system, because the vulnerable library may be present even when the host OS and network services appear clean. A host vulnerability scan targets installed OS packages, services, and local configuration, so it can miss third-party libraries bundled into custom application code. A container image scan can reveal base-image and OS-level packages, and it may find dependencies if build-time artifacts remain, but it is not the precise control for application dependency enumeration in the same way as parsing application manifests. A network vulnerability scan probes reachable ports, services, and banner-level weaknesses, so it cannot reliably identify embedded open-source components inside an application. Exam caveat: CS0-004 may use software composition analysis and dependency analysis interchangeably when the question focuses on open-source components in application software. Operational check: collect the application's package manifest or lockfile, generate a software bill of materials, and match each component version against a maintained vulnerability feed.