Question 251
Open question ↗You have a Microsoft 365 tenant.
You have an Azure subscription that contains Azure App Service web apps. The apps have the following characteristics:
• The apps use third-party and open-source components.
• The apps were developed by using C#, Python, and Java.
• The app deployment process is managed by using Azure DevOps.
• The source code for the apps is stored in GitHub Enterprise Cloud repositories and protected by using GitHub Advanced Security.
You need to reduce the risk of supply chain attacks during the application lifecycle.
What should you implement?
- A.secret scanning
- B.Dependabot alerts
- C.app governance in Microsoft Defender for Cloud Apps
- D.NuGet Audit



