Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard

A development team is implementing a CI/CD pipeline for a cloud-native application. The security team wants to integrate security checks early in the development process to identify vulnerabilities in code and configurations before deployment. They aim to 'shift left' security. Which practice is most aligned with this 'shift left' security principle in a CI/CD pipeline?

  1. AImplementing a Web Application Firewall (WAF) in front of the deployed application.
  2. BConducting penetration testing on the production environment after deployment.
  3. CPerforming annual security audits of the cloud provider's infrastructure.
  4. DIntegrating static application security testing (SAST) and infrastructure as code (IaC) scanning into the build stage.
Show answer & explanation

Correct answer: D. Integrating static application security testing (SAST) and infrastructure as code (IaC) scanning into the build stage.

Shifting left security means integrating security practices early in the development lifecycle. Integrating SAST (Static Application Security Testing) for code analysis and IaC scanning for configuration vulnerabilities into the build stage of the CI/CD pipeline directly embodies this principle by catching issues before deployment.

Why the other options are wrong

  • A. A WAF protects the deployed application, but it's a runtime control and doesn't identify vulnerabilities during development, thus not 'shift left.'
  • B. Penetration testing in production occurs late in the lifecycle and is a 'shift right' activity, not 'shift left.'
  • C. Auditing the cloud provider's infrastructure is part of shared responsibility and ongoing governance, but not a 'shift left' practice for application development security.

Shift Left Security

The practice of integrating security testing and practices earlier in the software development lifecycle (SDLC) to identify and remediate vulnerabilities sooner.

  • Reduces cost and effort of fixing vulnerabilities.
  • Involves security testing in design, code, and build phases.
  • Common in DevOps and CI/CD pipelines.

Memory trick: Shift Left: Security checks move to the start of the pipeline.

More Cloud Security questions