Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A global technology company is developing a new suite of microservices-based applications deployed on Kubernetes in a multi-cloud environment. The company needs to enforce consistent security policies, manage secrets, and ensure compliance across all development, staging, and production environments, while maintaining rapid development cycles. The cybersecurity architect must choose a GRC technical strategy that integrates seamlessly into their CI/CD pipelines. Which strategy is MOST effective in this scenario?
- AEstablishing a traditional Vulnerability Management (VM) program with quarterly scans.
- BImplementing a centralized Security Information and Event Management (SIEM) system.
- CUtilizing a Data Loss Prevention (DLP) system for monitoring data exfiltration from containers.
- DDeploying a cloud-native secrets management solution and policy-as-code for infrastructure.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploying a cloud-native secrets management solution and policy-as-code for infrastructure.
For microservices and Kubernetes in multi-cloud, a cloud-native secrets management solution handles sensitive data, while policy-as-code ensures consistent security and compliance enforcement directly within CI/CD pipelines, supporting rapid development.
Why the other options are wrong
- A. Traditional VM with quarterly scans is too slow and reactive for rapid, microservices-based development cycles and multi-cloud environments.
- B. SIEM is for log aggregation and incident detection, not for enforcing security policies or managing secrets within CI/CD pipelines for cloud-native applications.
- C. DLP is focused on preventing data leakage and does not address the broader needs of policy enforcement, secrets management, and compliance within CI/CD for cloud-native applications.
Policy-as-Code & Cloud-Native Secrets Management
Policy-as-Code defines security and compliance policies in machine-readable code, while cloud-native secrets management secures and distributes sensitive credentials in dynamic cloud environments.
- Automates policy enforcement in CI/CD.
- Ensures consistent security across environments.
- Secures API keys, database credentials, etc., for microservices.
Memory trick: Policy-as-Code and Secrets Management are the 'Guardians' of 'Cloud-Native Deployments'.