Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy
A financial services organization is adopting a DevOps methodology for its application development. The cybersecurity architect needs to integrate security into the CI/CD pipeline to meet regulatory requirements for secure development and change management. Which technical strategy provides the most effective approach for 'shifting left' security controls within this environment?
- ARelying solely on developers to manually review code for security vulnerabilities before deployment.
- BDeploying a web application firewall (WAF) in front of production applications as the primary security control.
- CConducting annual penetration tests on production systems only.
- DImplementing automated static application security testing (SAST) and dynamic application security testing (DAST) in the CI/CD pipeline, along with automated security configuration checks.
Show answer & explanationAnswer & explanation
Correct answer: D. Implementing automated static application security testing (SAST) and dynamic application security testing (DAST) in the CI/CD pipeline, along with automated security configuration checks.
Integrating SAST, DAST, and automated security configuration checks directly into the CI/CD pipeline allows for early detection and remediation of vulnerabilities, aligning with the 'shift left' principle and improving overall security posture and compliance.
Why the other options are wrong
- A. Manual code review by developers is prone to human error, inconsistent, and does not scale with fast-paced DevOps pipelines.
- B. A WAF is a production-level defensive control; it does not 'shift left' security into the development process where vulnerabilities are introduced.
- C. Annual penetration tests on production are too late in the development cycle to effectively 'shift left' and are insufficient for continuous compliance in a DevOps environment.
Shift Left Security
The practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to find and fix vulnerabilities when they are less costly.
- Reduces the cost and effort of fixing security defects.
- Promotes a culture of security awareness among developers.
- Often involves automated security testing tools in CI/CD pipelines.
Memory trick: Move Security Left, Catch Bugs Early