A security architect is evaluating a new cloud-native application for potential vulnerabilities. The application uses serverless functions that interact with a managed database and object storage. Traditional network-based vulnerability scanners are struggling to provide comprehensive coverage. Which of the following approaches would be MOST effective for identifying security weaknesses in this environment?
- APerforming regular external penetration testing against the application's public endpoints.
- BDeploying host-based vulnerability scanners on the underlying cloud compute instances.
- CImplementing a web application firewall (WAF) to block known attack patterns.
- DUtilizing cloud security posture management (CSPM) tools and reviewing Infrastructure-as-Code (IaC) configurations.
Show answer & explanationAnswer & explanation
Correct answer: D. Utilizing cloud security posture management (CSPM) tools and reviewing Infrastructure-as-Code (IaC) configurations.
Cloud-native and serverless environments often have ephemeral resources and are defined by code (IaC). CSPM tools are designed to continuously assess cloud configurations against security best practices and compliance benchmarks, while reviewing IaC ensures that security is built-in from the start, making these the most effective for finding vulnerabilities in such environments.
Why the other options are wrong
- A. External penetration testing is important but may miss misconfigurations or vulnerabilities in internal serverless functions and managed services not exposed publicly.
- B. Host-based scanners are largely irrelevant for serverless functions and managed databases, as the underlying compute instances are abstracted away and not directly user-manageable.
- C. A WAF protects against common web attacks but doesn't identify misconfigurations or vulnerabilities within the serverless function code, database, or object storage itself.
Cloud Security Posture Management (CSPM)
A category of security tools that continuously monitor cloud environments for misconfigurations, compliance violations, and security risks, providing visibility and automated remediation recommendations.
- Automates security assessments across cloud services.
- Detects misconfigurations, policy violations, and compliance gaps.
- Essential for managing security in dynamic cloud environments.
Memory trick: Cloud apps need cloud tools for security checks.