Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesMedium

A multinational technology company is developing a new suite of microservices-based applications deployed across hybrid cloud environments. To ensure continuous compliance and agility, the cybersecurity architect wants to embed security policies directly into the development and deployment workflows, automating policy enforcement and configuration management. Which GRC technical strategy is BEST suited for this 'security as code' approach?

  1. ADeploying a standalone Cloud Access Security Broker (CASB) for cloud application monitoring.
  2. BAdopting Policy-as-Code (PaC) integrated into CI/CD pipelines with automated enforcement.
  3. CImplementing traditional manual security audits and compliance checks.
  4. DUtilizing a centralized GRC platform for post-deployment compliance reporting.
Show answer & explanation

Correct answer: B. Adopting Policy-as-Code (PaC) integrated into CI/CD pipelines with automated enforcement.

Policy-as-Code (PaC) allows security policies to be defined, managed, and enforced as code, directly integrating into CI/CD pipelines. This automates policy checks and enforcement during development and deployment, ensuring continuous compliance and configuration management in dynamic microservices and hybrid cloud environments.

Why the other options are wrong

  • A. A CASB monitors cloud application usage and data, but it doesn't primarily focus on embedding and enforcing infrastructure or application security policies as code within CI/CD pipelines.
  • C. Manual audits are slow, error-prone, and not scalable for continuous compliance in agile, microservices environments.
  • D. A centralized GRC platform is for reporting and managing compliance but typically doesn't embed policy enforcement directly into development pipelines for automated, pre-deployment checks.

Policy-as-Code (PaC)

Policy-as-Code defines and enforces security, compliance, and operational policies using machine-readable code, integrating them directly into development and deployment workflows.

  • Automates policy enforcement.
  • Integrates with CI/CD pipelines.
  • Ensures consistent security across environments.

Memory trick: For agile security, policies are code, checked in the pipeline.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions