Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A company is developing a new cloud-native application using serverless functions and containers. The security team wants to embed security checks throughout the CI/CD pipeline, from code commit to deployment, to identify vulnerabilities and misconfigurations as early as possible. This approach aims to reduce the cost and effort of fixing security issues later in the development lifecycle. Which security principle or methodology are they applying?
- ADevSecOps
- BData Loss Prevention (DLP)
- CSecurity Information and Event Management (SIEM)
- DZero Trust
Show answer & explanationAnswer & explanation
Correct answer: A. DevSecOps
DevSecOps integrates security practices into every phase of the software development lifecycle (SDLC), shifting security 'left' to find and fix issues earlier, which aligns with embedding security checks throughout the CI/CD pipeline.
Why the other options are wrong
- B. DLP focuses on preventing sensitive data exfiltration, not embedding security into the development pipeline.
- C. SIEM aggregates and analyzes security logs for threat detection, it's an operational tool, not a development methodology.
- D. Zero Trust is a security model based on 'never trust, always verify', not primarily a development methodology.
DevSecOps
An approach that integrates security into every phase of the software development lifecycle (SDLC), from design and development to operations, emphasizing automation and collaboration.
- Shifts security 'left' (earlier in SDLC).
- Automates security testing within CI/CD pipelines.
- Fosters collaboration between development, security, and operations teams.
Memory trick: DevSecOps is like a seatbelt for your code, put it on at the start of the journey.