AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium
A company is implementing a new CI/CD pipeline for its serverless applications using AWS CodePipeline. They need to ensure that all Lambda functions are scanned for common vulnerabilities and adherence to security best practices before deployment to production. The security team also requires that these scans are integrated seamlessly into the pipeline and can block deployments if critical issues are found. Which combination of AWS services should the DevOps engineer integrate into the CodePipeline for automated security scanning?
- AAWS GuardDuty and AWS Shield Advanced
- BAmazon Macie and AWS WAF
- CAWS Config and AWS CloudTrail
- DAWS Security Hub and Amazon Inspector
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Security Hub and Amazon Inspector
Amazon Inspector can scan Lambda functions for vulnerabilities and adherence to security best practices. AWS Security Hub can aggregate findings from Inspector and other services, providing a centralized view and allowing for automated response actions, including blocking deployments based on critical findings.
Why the other options are wrong
- A. GuardDuty is for threat detection, and Shield Advanced is for DDoS protection; neither performs code/function vulnerability scanning.
- B. Macie is for data discovery and protection in S3, and WAF is a web application firewall; neither scans Lambda code for vulnerabilities.
- C. Config monitors resource configuration, and CloudTrail logs API activity; neither performs vulnerability scanning of application code.
Automated Security Scanning in CI/CD
Integrating tools into a CI/CD pipeline to automatically identify security vulnerabilities, misconfigurations, and policy violations in code and infrastructure before deployment.
- Shifts security left in the development lifecycle.
- Reduces human error and speeds up security feedback.
- Can block deployments for critical issues.
Memory trick: Inspector finds flaws, Security Hub unites and acts.