AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceHard
A DevOps team needs to implement a solution to automatically identify and flag exposed access keys, sensitive data in plain text, and other credentials that might be accidentally pushed to public or private GitHub repositories. This solution must integrate with AWS services and provide alerts to the security team. Which AWS service is specifically designed for this type of secret detection in code repositories?
- AAWS Security Hub
- BAWS GuardDuty
- CAmazon Macie
- DAmazon CodeGuru Security
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon CodeGuru Security
Amazon CodeGuru Security is a static application security testing (SAST) service that analyzes code for security vulnerabilities, including hardcoded secrets, sensitive data exposure, and other security policy violations. It integrates with code repositories like GitHub and AWS CodeCommit to provide findings and alerts.
Why the other options are wrong
- A. Security Hub is a centralized security posture management service that aggregates findings from various AWS services, but it does not perform the actual secret detection in code itself.
- B. GuardDuty monitors for malicious activity and unauthorized behavior in AWS accounts, not for secrets in code repositories.
- C. Macie is a data security and data privacy service that discovers and protects sensitive data in S3 buckets, not in code repositories.
Amazon CodeGuru Security
An AWS machine learning-powered service that automatically finds security vulnerabilities in your application code and provides recommendations to fix them. It can detect issues like hardcoded secrets, sensitive data exposure, injection flaws, and more.
- Static Application Security Testing (SAST).
- Detects security vulnerabilities and hardcoded secrets in code.
- Integrates with popular code repositories (e.g., GitHub, CodeCommit).
Memory trick: CodeGuru Security is the 'secret detective' of your code repositories.