Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityEasy

An organization is adopting a policy to ensure that all container images deployed in their Kubernetes cluster are scanned for known vulnerabilities before they are even built or pushed to a registry. This proactive approach aims to catch security issues as early as possible in the development pipeline. Which of the following best describes this security philosophy?

  1. ASecrets Management
  2. BIdentity and Access Management
  3. CRuntime Security Monitoring
  4. DShift-Left Security
Show answer & explanation

Correct answer: D. Shift-Left Security

Shift-Left Security emphasizes integrating security practices and testing into the earliest stages of the software development lifecycle, such as during code writing and image building, to identify and remediate vulnerabilities proactively.

Why the other options are wrong

  • A. Secrets Management deals with securing sensitive credentials, not proactive vulnerability scanning in the pipeline.
  • B. Identity and Access Management controls who can do what, which is different from early vulnerability detection in images.
  • C. Runtime Security Monitoring focuses on detecting threats during the execution phase, which is 'shifted right'.

Shift-Left Security

A software development approach where security considerations and practices are integrated into the earliest possible stages of the development lifecycle, rather than being addressed at the end.

  • Identifies vulnerabilities early.
  • Reduces cost and effort of remediation.
  • Integrates security into CI/CD pipelines.

Memory trick: Shift left, catch threats early.

More Cloud Native Security questions