A global software development company is adopting a DevSecOps approach within its Zero Trust strategy. They use Azure DevOps for their CI/CD pipelines and GitHub for source code management. The security team needs to ensure that security vulnerabilities are identified early in the development lifecycle, specifically within the source code itself and during application runtime, before deployment to production. The solution should be integrated into the existing pipelines to automate security checks.
- ADeploy Web Application Firewalls (WAFs) in front of all production applications.
- BImplement extensive manual code reviews by security experts at each release stage.
- CIntegrate Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools into the CI/CD pipeline.
- DConduct penetration testing annually on all production applications.
Show answer & explanationAnswer & explanation
Correct answer: C. Integrate Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools into the CI/CD pipeline.
Integrating SAST and DAST tools directly into the CI/CD pipeline is a cornerstone of DevSecOps. SAST analyzes source code for vulnerabilities before compilation, while DAST tests the running application for vulnerabilities, simulating attacks. This combination identifies issues early and continuously, aligning with the Zero Trust principle of 'assume breach' and shifting security left.
Why the other options are wrong
- A. WAFs protect against attacks in production but do not identify vulnerabilities within the source code or application during the development phase.
- B. Manual code reviews are time-consuming, not scalable, and do not provide continuous, automated security checks.
- D. Annual penetration testing is a reactive measure for production systems and does not integrate security checks early into the development lifecycle.
Static Application Security Testing (SAST) & Dynamic Application Security Testing (DAST)
SAST analyzes application source code for vulnerabilities without executing it, while DAST tests the running application for vulnerabilities by simulating attacks.
- SAST: 'White-box' testing, ideal for early detection in development.
- DAST: 'Black-box' testing, finds runtime vulnerabilities and configuration issues.
- Both are crucial for a comprehensive DevSecOps security strategy.
- Integrate into CI/CD pipelines for automated and continuous security.
Memory trick: SAST/DAST: Secure Apps, Start Today, Detect Attacks Sooner, Test.