CompTIA Security+ (SY0-701)Security ArchitectureMedium
A DevOps team uses an Infrastructure as Code (IaC) template to provision a new cloud storage bucket. After deployment, a security audit finds the bucket is publicly readable by anyone on the internet. Which practice would have MOST effectively prevented this issue?
- AConfiguring a content delivery network in front of the bucket
- BEncrypting the bucket contents with a customer-managed key
- CScanning the IaC template for misconfigurations before deployment
- DEnabling versioning on the storage bucket
Show answer & explanationAnswer & explanation
Correct answer: C. Scanning the IaC template for misconfigurations before deployment
IaC templates should be scanned by static analysis/policy-as-code tools before deployment to catch insecure defaults like public access, preventing the misconfiguration from ever reaching production.
Why the other options are wrong
- A. A CDN improves performance/caching but does not fix underlying permission misconfigurations.
- B. Encryption does not stop unauthorized users from reading data if access controls are still public.
- D. Versioning protects against accidental deletion/overwrite, not public exposure.
IaC Security Scanning
The practice of statically analyzing Infrastructure as Code templates (e.g., Terraform, CloudFormation) for security misconfigurations before they are deployed.
- Also called 'shift-left' security testing
- Catches issues like public buckets, open security groups, missing encryption
- Integrated into CI/CD pipelines to block insecure deployments
Memory trick: 'Scan the blueprint before you build the house.'