Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy
An organization is adopting a policy to ensure that all container images deployed in their Kubernetes clusters are free from known vulnerabilities. They want to integrate this check into their CI/CD pipeline, failing builds if any critical vulnerabilities are detected before an image is pushed to the registry. Which security practice does this scenario primarily describe?
- ASecrets Management
- BRuntime Security Monitoring
- CShift-Left Security
- DNetwork Segmentation
Show answer & explanationAnswer & explanation
Correct answer: C. Shift-Left Security
Shift-Left Security emphasizes incorporating security practices and testing earlier in the development lifecycle (e.g., CI/CD pipeline). Detecting vulnerabilities before images are even pushed to a registry is a prime example of shifting security left.
Why the other options are wrong
- A. Secrets Management deals with the secure handling of sensitive data, which is unrelated to image vulnerability scanning.
- B. Runtime Security Monitoring focuses on detecting threats in *running* applications, not pre-deployment vulnerabilities.
- D. Network Segmentation involves dividing a network into smaller, isolated segments, which is a network security measure, not related to image scanning.
Shift-Left Security
An approach to security that integrates security practices and testing earlier in the software development lifecycle (SDLC), aiming to identify and mitigate vulnerabilities as early as possible.
- Moves security from the end to the beginning of the SDLC.
- Reduces cost and effort of fixing vulnerabilities.
- Includes practices like SAST, DAST, image scanning in CI/CD.
Memory trick: Shift Left means catching problems early, before they become big headaches.