Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy

An organization is adopting a policy to ensure that all container images deployed in their Kubernetes clusters are free from known vulnerabilities. They want to integrate this check into their CI/CD pipeline, failing builds if any critical vulnerabilities are detected before an image is pushed to the registry. Which security practice does this scenario primarily describe?

  1. ASecrets Management
  2. BRuntime Security Monitoring
  3. CShift-Left Security
  4. DNetwork Segmentation
Show answer & explanation

Correct answer: C. Shift-Left Security

Shift-Left Security emphasizes incorporating security practices and testing earlier in the development lifecycle (e.g., CI/CD pipeline). Detecting vulnerabilities before images are even pushed to a registry is a prime example of shifting security left.

Why the other options are wrong

  • A. Secrets Management deals with the secure handling of sensitive data, which is unrelated to image vulnerability scanning.
  • B. Runtime Security Monitoring focuses on detecting threats in *running* applications, not pre-deployment vulnerabilities.
  • D. Network Segmentation involves dividing a network into smaller, isolated segments, which is a network security measure, not related to image scanning.

Shift-Left Security

An approach to security that integrates security practices and testing earlier in the software development lifecycle (SDLC), aiming to identify and mitigate vulnerabilities as early as possible.

  • Moves security from the end to the beginning of the SDLC.
  • Reduces cost and effort of fixing vulnerabilities.
  • Includes practices like SAST, DAST, image scanning in CI/CD.

Memory trick: Shift Left means catching problems early, before they become big headaches.

More Cloud Native Security questions