Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesEasy

A financial services organization is adopting a DevOps methodology for its application development. The cybersecurity architect needs to integrate security into the CI/CD pipeline to meet regulatory requirements for secure development and change management. Which technical strategy provides the most effective approach for 'shifting left' security controls within this environment?

  1. ARelying solely on developers to manually review code for security vulnerabilities before deployment.
  2. BDeploying a web application firewall (WAF) in front of production applications as the primary security control.
  3. CConducting annual penetration tests on production systems only.
  4. DImplementing automated static application security testing (SAST) and dynamic application security testing (DAST) in the CI/CD pipeline, along with automated security configuration checks.
Show answer & explanation

Correct answer: D. Implementing automated static application security testing (SAST) and dynamic application security testing (DAST) in the CI/CD pipeline, along with automated security configuration checks.

Integrating SAST, DAST, and automated security configuration checks directly into the CI/CD pipeline allows for early detection and remediation of vulnerabilities, aligning with the 'shift left' principle and improving overall security posture and compliance.

Why the other options are wrong

  • A. Manual code review by developers is prone to human error, inconsistent, and does not scale with fast-paced DevOps pipelines.
  • B. A WAF is a production-level defensive control; it does not 'shift left' security into the development process where vulnerabilities are introduced.
  • C. Annual penetration tests on production are too late in the development cycle to effectively 'shift left' and are insufficient for continuous compliance in a DevOps environment.

Shift Left Security

The practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to find and fix vulnerabilities when they are less costly.

  • Reduces the cost and effort of fixing security defects.
  • Promotes a culture of security awareness among developers.
  • Often involves automated security testing tools in CI/CD pipelines.

Memory trick: Move Security Left, Catch Bugs Early

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions