Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security team wants to integrate security checks early into the development process for all new applications. This includes scanning source code for vulnerabilities, checking open-source components for known issues, and ensuring secure configuration of Azure resources deployed by CI/CD pipelines. The goal is to identify and remediate security flaws before they reach production. Which Azure service should the security architect integrate with Azure DevOps to achieve this 'shift-left' security approach?

  1. AMicrosoft Defender for Cloud - DevOps Security
  2. BAzure Network Watcher
  3. CAzure AD Identity Protection
  4. DAzure App Configuration
Show answer & explanation

Correct answer: A. Microsoft Defender for Cloud - DevOps Security

Microsoft Defender for Cloud's DevOps Security capabilities are specifically designed to integrate security into the development pipeline. It provides unified visibility, posture management, and threat protection across multi-pipeline environments, including vulnerability scanning for code and open-source components, and secure configuration checks.

Why the other options are wrong

  • B. Azure Network Watcher helps monitor and diagnose network performance and issues, not SDLC security.
  • C. Azure AD Identity Protection focuses on detecting and preventing identity-based risks, not SDLC security.
  • D. Azure App Configuration centralizes application settings and feature flags, not for DevOps security scanning.

Microsoft Defender for Cloud - DevOps Security

Microsoft Defender for Cloud's DevOps Security capabilities provide comprehensive security management across multi-pipeline environments, integrating security into the development lifecycle from code to cloud.

  • Unified visibility and posture management for DevOps.
  • Scans code, open-source components, and infrastructure-as-code.
  • Helps 'shift-left' security to identify vulnerabilities early.

Memory trick: Defender protects your code from the start of the DevOps journey.

More Design security for applications and data questions