Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A global manufacturing company uses Azure DevOps for its software development lifecycle (SDLC). The security architect needs to implement a 'shift-left' security strategy for their applications, ensuring that security vulnerabilities are identified and remediated as early as possible in the development process, ideally before code is even deployed to production. This includes scanning code for vulnerabilities, checking for misconfigurations in Infrastructure-as-Code (IaC) templates, and scanning container images. Which Azure service is central to implementing this strategy within Azure DevOps?
- AAzure Security Center (now Defender for Cloud) for runtime protection of deployed resources.
- BAzure Policy for enforcing compliance after deployment.
- CAzure Monitor for application performance monitoring and log analytics.
- DMicrosoft Defender for Cloud, integrated into Azure DevOps.
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Defender for Cloud, integrated into Azure DevOps.
Microsoft Defender for Cloud offers DevOps security capabilities that integrate directly into Azure DevOps pipelines, providing code scanning, IaC scanning, and container image scanning early in the SDLC, embodying a 'shift-left' approach.
Why the other options are wrong
- A. While Defender for Cloud does provide runtime protection, the question specifically asks for 'shift-left' capabilities *before* deployment within the SDLC. Option A correctly highlights its integrated DevOps security features for this purpose.
- B. Azure Policy enforces compliance at deployment and runtime, but it's not primarily a 'shift-left' tool for identifying code or IaC vulnerabilities during development.
- C. Azure Monitor is for operational insights, logging, and performance monitoring of deployed applications, not for 'shift-left' security in the development pipeline.
Microsoft Defender for Cloud - DevOps Security
A feature within Microsoft Defender for Cloud that provides comprehensive visibility, management, and security for the DevOps environment, enabling 'shift-left' security by integrating security into CI/CD pipelines.
- Scans code, IaC templates, and container images for vulnerabilities.
- Integrates with Azure DevOps, GitHub, and other DevOps platforms.
- Helps identify and remediate security issues early in the SDLC.
Memory trick: Defender for Cloud Shifts Security Left in DevOps.