CompTIA SecurityX (CAS-005)Security EngineeringMedium
A software development team is adopting a GitOps methodology for deploying and managing microservices in a Kubernetes cluster. As part of their continuous integration/continuous deployment (CI/CD) pipeline, they need to ensure that all changes to infrastructure and application configurations are automatically scanned for security vulnerabilities and policy compliance BEFORE being applied to the production environment. Which type of security testing is BEST suited for integrating into the GitOps workflow at the pre-deployment stage?
- AInfrastructure as Code (IaC) Security Scanning
- BDynamic Application Security Testing (DAST)
- CRuntime Application Self-Protection (RASP)
- DSoftware Composition Analysis (SCA)
Show answer & explanationAnswer & explanation
Correct answer: A. Infrastructure as Code (IaC) Security Scanning
Infrastructure as Code (IaC) Security Scanning is crucial for GitOps, as it analyzes configuration files (e.g., Kubernetes YAML, Terraform) before deployment to identify misconfigurations, policy violations, and potential vulnerabilities, ensuring security 'left shift'.
Why the other options are wrong
- B. DAST tests applications in a running state, which is a post-deployment activity, not suitable for pre-deployment scanning of configurations.
- C. RASP protects applications during runtime by instrumenting them, which is a post-deployment/runtime security measure, not a pre-deployment scanning tool.
- D. SCA focuses on identifying vulnerabilities in open-source components and libraries, which is important but doesn't cover the security of the infrastructure configuration itself.
Infrastructure as Code (IaC) Security Scanning
The process of analyzing Infrastructure as Code (IaC) definition files (e.g., Terraform, CloudFormation, Kubernetes YAML) for security misconfigurations, policy violations, and vulnerabilities before deployment.
- Integrates into CI/CD pipelines.
- Identifies security issues early ('shift left').
- Ensures compliance with security policies for infrastructure.
Memory trick: IaC Scanning Secures Infrastructure Early.