Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global software development company uses GitHub for source code management and Azure DevOps for CI/CD pipelines. They are implementing a Zero Trust strategy that extends to their development processes. The security team wants to ensure that all code changes undergo automated security analysis before deployment, identifying vulnerabilities early in the development lifecycle. Which two DevSecOps practices, when combined, would BEST achieve this Zero Trust objective?

  1. ARed Team exercises and Penetration Testing
  2. BStatic Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)
  3. CSecurity Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR)
  4. DVulnerability scanning and Patch Management
Show answer & explanation

Correct answer: B. Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST)

SAST analyzes source code for vulnerabilities without running the application, ideal for early detection in GitHub and Azure DevOps. DAST analyzes the running application for vulnerabilities, complementing SAST by finding issues only apparent at runtime. Together, they provide comprehensive automated security analysis throughout the development lifecycle, aligning with Zero Trust's 'never trust' approach to code.

Why the other options are wrong

  • A. Red Team exercises and Penetration Testing are typically manual, post-deployment assessments, not automated security analysis integrated into the CI/CD pipeline for early detection.
  • C. SIEM and SOAR are primarily for operational security monitoring and incident response, not for automated security analysis of code during development.
  • D. While vulnerability scanning (which can overlap with DAST for applications) and patch management are important, the combination of SAST and DAST specifically targets 'automated security analysis of code changes' throughout the development lifecycle, which is more comprehensive for this scenario.

SAST and DAST (DevSecOps Zero Trust)

Automated security testing methods integrated into the DevSecOps pipeline to identify vulnerabilities in source code (SAST) and running applications (DAST).

  • SAST: Static analysis, 'white box' testing, early detection.
  • DAST: Dynamic analysis, 'black box' testing, finds runtime issues.
  • Crucial for 'shifting left' security in Zero Trust development.

Memory trick: SAST and DAST find bugs before they blast.

More Design a Zero Trust strategy and architecture questions