Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy

A company is adopting a DevSecOps approach and wants to integrate security scanning into their CI/CD pipeline as early as possible. They aim to identify vulnerabilities in application code and dependencies before container images are even built. Which security testing method should they prioritize for this 'shift-left' strategy?

  1. AStatic Application Security Testing (SAST)
  2. BDynamic Application Security Testing (DAST)
  3. CRuntime Application Self-Protection (RASP)
  4. DContainer Image Vulnerability Scanning
Show answer & explanation

Correct answer: A. Static Application Security Testing (SAST)

Static Application Security Testing (SAST) is a 'shift-left' security method that analyzes application source code, bytecode, or binary code for vulnerabilities without actually executing the application. This allows developers to find and fix security issues early in the development lifecycle, before deployment.

Why the other options are wrong

  • B. DAST tests applications in their running state, which occurs later in the development lifecycle, not 'as early as possible'.
  • C. RASP protects applications during runtime and is a 'shift-right' security measure, not an early pipeline integration.
  • D. Container image scanning occurs after the image has been built, which is later than analyzing the source code itself.

Shift-Left Security (SAST)

A DevSecOps principle that advocates for integrating security practices and testing early in the software development lifecycle, such as using Static Application Security Testing (SAST) to analyze code for vulnerabilities.

  • Identifies vulnerabilities in source code before execution.
  • Helps developers fix issues early, reducing cost and effort.
  • Part of a proactive security strategy in CI/CD.

Memory trick: Shift Left: Secure early, save headaches later.

More Cloud Native Security questions