Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium
A large e-commerce company processes millions of transactions daily and is subject to PCI DSS compliance. The company is adopting a microservices architecture and uses containers extensively. The cybersecurity architect needs to implement a security operations strategy that provides real-time threat detection and response specifically for containerized applications within the Payment Card Industry (PCI) environment. Which strategy would be MOST effective?
- ARelying solely on static application security testing (SAST) during the CI/CD pipeline.
- BDeploying a dedicated Container Security Platform with runtime protection and compliance scanning.
- CUtilizing a perimeter-based firewall to protect the entire microservices cluster.
- DImplementing traditional host-based antivirus software on container hosts.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploying a dedicated Container Security Platform with runtime protection and compliance scanning.
A dedicated Container Security Platform provides specialized runtime protection for containerized applications, including threat detection, vulnerability scanning of images, and compliance checks tailored for container environments. This is crucial for real-time security and PCI DSS compliance in a microservices architecture.
Why the other options are wrong
- A. SAST is important for finding code vulnerabilities pre-deployment but does not provide real-time threat detection or runtime protection for active containerized applications in production.
- C. A perimeter firewall protects the network boundary but lacks visibility into intra-cluster container traffic and runtime behavior, which is critical for microservices security.
- D. Traditional host-based antivirus is not designed for the ephemeral and dynamic nature of containers and often lacks visibility into container-specific threats or compliance.
Container Security Platforms
These platforms provide comprehensive security for containerized applications throughout their lifecycle, including vulnerability management, runtime protection, and compliance.
- Scans container images for vulnerabilities.
- Monitors container runtime behavior for anomalies.
- Enforces security policies within container environments.
Memory trick: PCI containers need a specialized guard, not just the building's watchman.