CompTIA Security+ (SY0-701)Security ArchitectureMedium

A DevOps team uses an Infrastructure as Code (IaC) template to provision a new cloud storage bucket. After deployment, a security audit finds the bucket is publicly readable by anyone on the internet. Which practice would have MOST effectively prevented this issue?

  1. AConfiguring a content delivery network in front of the bucket
  2. BEncrypting the bucket contents with a customer-managed key
  3. CScanning the IaC template for misconfigurations before deployment
  4. DEnabling versioning on the storage bucket
Show answer & explanation

Correct answer: C. Scanning the IaC template for misconfigurations before deployment

IaC templates should be scanned by static analysis/policy-as-code tools before deployment to catch insecure defaults like public access, preventing the misconfiguration from ever reaching production.

Why the other options are wrong

  • A. A CDN improves performance/caching but does not fix underlying permission misconfigurations.
  • B. Encryption does not stop unauthorized users from reading data if access controls are still public.
  • D. Versioning protects against accidental deletion/overwrite, not public exposure.

IaC Security Scanning

The practice of statically analyzing Infrastructure as Code templates (e.g., Terraform, CloudFormation) for security misconfigurations before they are deployed.

  • Also called 'shift-left' security testing
  • Catches issues like public buckets, open security groups, missing encryption
  • Integrated into CI/CD pipelines to block insecure deployments

Memory trick: 'Scan the blueprint before you build the house.'

More Security Architecture questions